-
Notifications
You must be signed in to change notification settings - Fork 100
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🌱 Attach and sign SBOM to images #1055
Comments
Before signing: |
that attaches it, we need also to sign it after it was attached: e.g.
|
yes, sorry, thats what I (tried to) mean, that we need to attach before signing :D Bit slow this morning ☕ |
yup no worries, is just for reference for who is picking up this card |
doesn't really work |
Attempt to fix: #1228 and #1055 Signed-off-by: mudler <[email protected]>
* 🤖 Attach and sign SBOM Attempt to fix: #1228 and #1055 Signed-off-by: mudler <[email protected]> * 🤖 Remove bashism, imply that there is a '.sbom' image Signed-off-by: mudler <[email protected]> * Enhancements Signed-off-by: mudler <[email protected]> --------- Signed-off-by: mudler <[email protected]>
Is your feature request related to a problem? Please describe.
Now that we have a SBOM file, we can attach and sign that with cosign so it is signed along the process, and easily verifiable with the cosign CLI
Describe the solution you'd like
The CI to sign and attach sbom file automatically when signing images.
When we do this, also create a blog post for this explaining how users can see the SBOM of the images, validate the image and the SBOM. Also show how to use
grype
to generate a security report from it.Describe alternatives you've considered
Additional context
https://docs.sigstore.dev/cosign/other_types/
The text was updated successfully, but these errors were encountered: