Carlos Tadeu Panato Junior
Carlos Tadeu Panato Junior
we need to wait for https://github.com/anchore/sbom-action/pull/456
Hello! I will start the work on this
To solve that issue, we could maybe sign the image in the release pipeline instead of the reusable workflow, which would make it easier to verify the signatures. Wdyt @sagikazarmark?
also i can implement the slsa generator if that is something we all want
the slsa generator will be another job after this one https://github.com/dexidp/dex/blob/master/.github/workflows/artifacts.yaml#L31 if you want to make that for both release and main branch, if we just want that to the...
@dependabot rebase
sorry for the delay, I will need a bit more time to review and have others to review as well cc @haydentherapper
we are not publishing that anymore, was only in the beginning. but you can use `cosign verify` to get all the information. I would say we update the docs to...
ok will update the docs
sample email sent 