-
Notifications
You must be signed in to change notification settings - Fork 211
Open
Description
Based on my understanding, we can use your signing key, which allows us to verify the integrity of the tarballs.
However, I as far I know, the docker images themselves are not signed because the source code does not appear to indicate that the images are being signed
Can we please sign the images with tools like cosign?
If there is any supported method to verify the images, please direct me as needed
Additional context: https://forums.swift.org/t/how-to-validate-the-integrity-of-the-docker-images/82916
Metadata
Metadata
Assignees
Labels
No labels