-
Notifications
You must be signed in to change notification settings - Fork 112
Open
Labels
enhancementNew feature or requestNew feature or requestsecurity-devsecopsSecurity features to improve the security posture and implement DevSecpOpsSecurity features to improve the security posture and implement DevSecpOps
Description
Description
Implement sigstore/cosign for adding provenance and signing the container image in GitHub Action CI.
Use Case
Once the image is built in the CI and should be signed in the GHA CI.
Proposed Solution
Implement and document the use of cosign in the CI. Document why it's needed.
Benefits
Secure use of container images.
Example
Additional Information
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestsecurity-devsecopsSecurity features to improve the security posture and implement DevSecpOpsSecurity features to improve the security posture and implement DevSecpOps