community
community copied to clipboard
Proposal: Framework for storing and managing system generated non-artifact data within the registry
@goharbor/all-maintainers can you please take a look and approve/ review vote for the proposal?
@goharbor/all-maintainers bumping @prahaladdarkin's message
can you please take a look and approve/ review vote for the proposal?
This might be important for this proposal.
From: https://github.com/opencontainers/tob/blob/main/proposals/wg-reference-types.md
As cloud native development continues to grow, there is increased interest in evolving registries to natively store, discover, and pull a graph of content associated with specific container images in a registry. Use cases for said associated artifacts include but are not limited to Software Bill of Materials (SBoM), security scan results, and signing. Having a native way to store and discover artifacts associated with other artifacts enables end-users to answer the question of: “What SBOMs or signatures are associated with this container image?”
@prahaladdarkin this can be merged.
@Vad1mo - can you please check this one so we can close it, as we have it in 2.5