Skip to content

Build provenance and SBOM attestations for images #8610

@nflaig

Description

@nflaig

Should consider adding this, right now there isn't a good way to verify the code you are running hasn't been tempered with when using a docker image.

See serenita-org/vero#224

Metadata

Metadata

Assignees

No one assigned

    Labels

    scope-securityIssues that fix security issues: DOS, key leak, CVEs.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions