Sign published container images - #227
Conversation
acidghost
left a comment
There was a problem hiding this comment.
LGTM!
You could also sign the SBOM as attestations: extract the SBOM and issue cosign attest over the file. I ended up updating my repo after opening the issue here 😅 (ref1, ref2). Downstream consumers might require the signature on the attestations before trusting the predicate (eg extractPayload from Kyverno).
9c7b6ef to
dc5c7fd
Compare
|
Rebased onto main (picks up #230 multi-arch and #232 login-action bump; dropped the now-duplicate Opened #236 to track |
Adds keyless Cosign signing for published container images. Enables full provenance and SBOM attestations in Buildx, then verifies both are present in GHCR.
Closes #225