lifecycle-toolkit
lifecycle-toolkit copied to clipboard
Generate and attest provenance for images
Goal
Generate and Attest Provenance for our images using docker/build-push-action.
Details
It will be good to generate and attest provenance for the images being. This can be easily done via the build action that we are currently using docker/build-push-action.
References
https://docs.docker.com/build/ci/github-actions/attestations/
DoD
- Provenance is being generated and attested for every released image.
- Provenance is not generated for CI builds
hii @rakshitgondwal, I wd like to do it
Sure, go ahead @prakrit55