Skip to content

Sign attestation manifests #5

@crazy-max

Description

@crazy-max

With these secure reusable workflows we want to have the ability to sign The BuildKit-generated provenance and SBOM attestations. This will be a step in our reusable workflows and not part of regular builds with BuildKit.

We want signatures pushed by digest unlike cosign that pushes a tag matching the signed manifest using the format <repo>/<image>:sha256-<manifest-digest>.sig. Verification will be done using the OCI Referrers API.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions