-
Notifications
You must be signed in to change notification settings - Fork 599
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Attest support for Singularity images #1193
Comments
As discussed in yesterday's community call, I'm not 100% sure what the workflow(s) should look like here. SIF is able to store arbitrary data within the image itself, and this may well be the expected behaviour of the average Singularity user. In other words, Leveraging Rekor and/or an OCI registry to store the attestation might also be compelling. |
What would you like to be added:
Support for the
singularity
image source in thesyft attest
command.Why is this needed:
Singularity users are able to generate an SBOM from their SIF image using Syft. It's a natural next step for them to want to include the SBOM in an attestation. Although this is possible without support directly in Syft, having it directly included would simplify user workflows.
Additional context:
The behaviour at the moment:
The text was updated successfully, but these errors were encountered: