Skip to content

Conversation

@candrews
Copy link

@candrews candrews commented May 2, 2024

  • Attach provenance attestation to the docker images
The provenance attestations include facts about the build process.

See: https://docs.docker.com/build/attestations/slsa-provenance/
  • Attach sbom attestation to docker images
Software Bill of Materials (SBOM) attestations describe what software artifacts an image contains, and artifacts used to create the image.

See: https://docs.docker.com/build/attestations/sbom/

candrews added 2 commits May 2, 2024 09:37
Software Bill of Materials (SBOM) attestations describe what software artifacts an image contains, and artifacts used to create the image.

See: https://docs.docker.com/build/attestations/sbom/
The provenance attestations include facts about the build process.

See: https://docs.docker.com/build/attestations/slsa-provenance/
@ozbillwang
Copy link
Contributor

Let me go through the related documents first, never used them before.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants