-
Notifications
You must be signed in to change notification settings - Fork 84
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ci: Generate and sign provenance information as image layer for SLSA …
…lvl 3 (#504) * ci: Generate and sign provenance info as image layer Configure docker buildx to generate provenance attestations as explained in https://docs.docker.com/build/metadata/attestations/slsa-provenance. Find the specific layer digest that corresponds to that provenance attestation, both for linux/amd64 and linux/arm64 architectures, and sign it. Signed-off-by: Víctor Cuadrado Juan <vcuadradojuan@suse.de> * ci: Use github.repository_owner instead of hardcoded org This allows to test the CI workflows in a fork, and to not need push permissions to production OCI registry namespace under ghcr.io/kyverno. Signed-off-by: Víctor Cuadrado Juan <vcuadradojuan@suse.de> --------- Signed-off-by: Víctor Cuadrado Juan <vcuadradojuan@suse.de>
- Loading branch information
Showing
2 changed files
with
90 additions
and
20 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters