Skip to content

Every image this repo ships is signed and carries its bill of materials #1301

Description

@ExtraToast

Parent

#1289

What to build

Nothing signs the images this repository publishes and nothing records what went into them. Sign with keyless cosign under the workflow's own identity, and publish provenance and SBOM attestations alongside each image.

This is advisory until admission enforcement exists. Nothing stops the cluster running an unsigned image, and the gap should not be mistaken for a guarantee.

Acceptance criteria

  • Every image published by this repository is signed, and the signature verifies against the workflow identity
  • Provenance and SBOM attestations are attached to each image
  • The verification command is written where an incident responder will find it
  • The absence of admission enforcement is recorded as a known gap

Blocked by

None (can start immediately).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:ci-cdpriority/4-laterWorth doing, waiting on a decision or on earlier slices.ready-for-agentSized and specified for an agent to pick upsecurity

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions