Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate and attest provenance for images #3310

Open
rakshitgondwal opened this issue Mar 20, 2024 · 2 comments · May be fixed by #3421
Open

Generate and attest provenance for images #3310

rakshitgondwal opened this issue Mar 20, 2024 · 2 comments · May be fixed by #3421
Assignees

Comments

@rakshitgondwal
Copy link
Member

rakshitgondwal commented Mar 20, 2024

Goal

Generate and Attest Provenance for our images using docker/build-push-action.

Details

It will be good to generate and attest provenance for the images being. This can be easily done via the build action that we are currently using docker/build-push-action.

References

https://docs.docker.com/build/ci/github-actions/attestations/

DoD

  • Provenance is being generated and attested for every released image.
  • Provenance is not generated for CI builds
@rakshitgondwal rakshitgondwal added enhancement New feature or request security labels Mar 20, 2024
@mowies mowies added the status: ready-for-refinement Issue is relevant for the next backlog refinment label Mar 20, 2024
@mowies mowies removed the status: ready-for-refinement Issue is relevant for the next backlog refinment label Apr 3, 2024
@prakrit55
Copy link
Member

hii @rakshitgondwal, I wd like to do it

@rakshitgondwal
Copy link
Member Author

Sure, go ahead @prakrit55

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: No status
Development

Successfully merging a pull request may close this issue.

3 participants