You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If a scan is run on an image in a registry, for example, it might be useful to sign the SBOM with Sigstore and upload it to a known artifact location so users are able to associate images with this trusted information.
NOTE: this is likely to require some additional configuration options for pushing to registries, use a signing key, etc.. and may be better served as a separate action.
The text was updated successfully, but these errors were encountered:
I love this. I could see it as a separate action, as you point out, but I also like the idea of combining it here as an optional step (but automatic once configured), for the sake of "making it easy to do security right".
If a scan is run on an image in a registry, for example, it might be useful to sign the SBOM with Sigstore and upload it to a known artifact location so users are able to associate images with this trusted information.
NOTE: this is likely to require some additional configuration options for pushing to registries, use a signing key, etc.. and may be better served as a separate action.
The text was updated successfully, but these errors were encountered: