New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(sbom): scan sbom attestation in the rekor record #2699
Conversation
|
pkg/flag/scan_flags.go
Outdated
SbomFromFlag = Flag{ | ||
Name: "sbom-from", | ||
ConfigName: "scan.sbom-from", | ||
Value: "", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Value: "", | |
Value: []string{}, |
pkg/flag/scan_flags.go
Outdated
Name: "sbom-from", | ||
ConfigName: "scan.sbom-from", | ||
Value: "", | ||
Usage: "comma-separated list of SBOM source (rekor)", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Usage: "comma-separated list of SBOM source (rekor)", | |
Usage: "EXPERIMENTAL: SBOM sources (rekor)", |
pkg/flag/scan_flags.go
Outdated
Name: "rekor-url", | ||
ConfigName: "scan.rekor-url", | ||
Value: "https://rekor.sigstore.dev", | ||
Usage: "URL of rekor server (default \"https://rekor.sigstore.dev\")", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The default value is shown by Cobra.
--rekor-url string URL of rekor server (default "https://rekor.sigstore.dev") (default "https://rekor.sigstore.dev")
pkg/fanal/artifact/image/image.go
Outdated
if err == nil { | ||
return results, nil | ||
} | ||
log.Logger.Debugf("Failed to inspect SBOM Attestation from rekor") |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We probably should distinguish between expected and unexpected errors.
Description
Result
Related issues
Checklist