You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The build pipeline should be signing the OCI image created and attesting the generated SBOM to the OCI registry alongside the image built during the pipeline run. This also means determining what kind of keys will be used to sign and where they can be securely stored (if necessary).
Acceptance Criteria
Use cosign Github Action(s) to sign the image produced in a pipeline
Use cosign Github Action(s) to attest the image's SBOM
The text was updated successfully, but these errors were encountered:
The Need
The build pipeline should be signing the OCI image created and attesting the generated SBOM to the OCI registry alongside the image built during the pipeline run. This also means determining what kind of keys will be used to sign and where they can be securely stored (if necessary).
Acceptance Criteria
cosign
Github Action(s) to sign the image produced in a pipelinecosign
Github Action(s) to attest the image's SBOMThe text was updated successfully, but these errors were encountered: