devsecops-demo icon indicating copy to clipboard operation
devsecops-demo copied to clipboard

Use Cosign and Sigstore to sign the images that are in the registry

Open rcarrata opened this issue 3 years ago • 3 comments

  • https://github.com/sigstore/cosign#registry-support

Possible Issue: Quay needs to be used, because the OCP Internal registry it's not supported.

rcarrata avatar Dec 16 '21 16:12 rcarrata

Added in ACS the possibility to check directly the Cosign Image -> https://openshift-docs-i4nuv2png-kcarmichael08.vercel.app/openshift-acs/master/operating/verify-image-signatures.html#configure-signature-integration_verify-image-signatures

rcarrata avatar Jun 05 '22 20:06 rcarrata

Started this feature- https://github.com/MoOyeg/devsecops-demo.git. I will push when complete.

MoOyeg avatar Jul 08 '22 15:07 MoOyeg

great!!! thanks for your work @MoOyeg++ !!

rcarrata avatar Jul 08 '22 17:07 rcarrata