rfcs icon indicating copy to clipboard operation
rfcs copied to clipboard

Add RFC for cosign integration

Open sambhav opened this issue 4 years ago • 7 comments

Signed-off-by: Sambhav Kothari [email protected]

Fixes #192

Readable

Debatable points -

  • Dealing with daemon use case?
  • pack v/s lifecycle support?
  • SBOM future (for now this just exports the SBOM in cosign format but also continues to use the existing way of storing it in the app image for restore/rebuild)

sambhav avatar Dec 03 '21 02:12 sambhav

Maintainers,

As you review this RFC please queue up issues to be created using the following commands:

/queue-issue <repo> "<title>" [labels]...
/unqueue-issue <uid>

Issues

(none)

buildpack-bot avatar Dec 03 '21 02:12 buildpack-bot

Cosign maintainer here! We'd love any feedback on the SBOM use case. This is really just a first draft based on how we guessed people might use it. If there's anything you don't like or we could change to make things easier we can do that! I'm excited to see it used here at all.

dlorenc avatar Dec 03 '21 03:12 dlorenc

If I recall correctly, this RFC falls under the same idea as other external operations such as preparer. Those of which I believe we would develop PoCs independently and try to incorporate back into the project via these guidelines. If so, should this be a draft or closed?

I would prefer if this was a repo under buildpacks org, potentially under the platform team since pack would be the first target usecase. It would make it easier to manage/review/depend on repositories that fall under the buildpacks org umbrella.

sambhav avatar Mar 24 '22 10:03 sambhav

Is the only outstanding issue of how we proceed with a PoC/where the work happens?

hone avatar Apr 06 '22 17:04 hone

Is the only outstanding issue of how we proceed with a PoC/where the work happens?

Pretty much

sambhav avatar Apr 06 '22 22:04 sambhav

@samj1912 as we discussed, this RFC requires a few set of changes to align with the latest agreed upon strategy. Please let me know when it's updated and I'll review/start the voting period.

jromero avatar May 27 '22 15:05 jromero

@samj1912 what is the status of this RFC? Is this still something we want to do?

natalieparellano avatar Nov 30 '22 14:11 natalieparellano