Skip to content

Sign attestation manifests #5

@crazy-max

Description

@crazy-max

With these secure reusable workflows we want to have the ability to sign The BuildKit-generated provenance and SBOM attestations. This will be a step in our reusable workflows and not part of regular builds with BuildKit.

We want signatures pushed by digest unlike cosign that pushes a tag matching the signed manifest using the format <repo>/<image>:sha256-<manifest-digest>.sig. Verification will be done using the OCI Referrers API.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions