lifecycle-toolkit icon indicating copy to clipboard operation
lifecycle-toolkit copied to clipboard

Generate and attest provenance for images

Open rakshitgondwal opened this issue 1 year ago • 2 comments

Goal

Generate and Attest Provenance for our images using docker/build-push-action.

Details

It will be good to generate and attest provenance for the images being. This can be easily done via the build action that we are currently using docker/build-push-action.

References

https://docs.docker.com/build/ci/github-actions/attestations/

DoD

  • Provenance is being generated and attested for every released image.
  • Provenance is not generated for CI builds

rakshitgondwal avatar Mar 20 '24 12:03 rakshitgondwal

hii @rakshitgondwal, I wd like to do it

prakrit55 avatar Apr 11 '24 12:04 prakrit55

Sure, go ahead @prakrit55

rakshitgondwal avatar Apr 11 '24 21:04 rakshitgondwal