Skip to content

Sign images #512

@yeikel

Description

@yeikel

Based on my understanding, we can use your signing key, which allows us to verify the integrity of the tarballs.

However, I as far I know, the docker images themselves are not signed because the source code does not appear to indicate that the images are being signed

Can we please sign the images with tools like cosign?

If there is any supported method to verify the images, please direct me as needed

Additional context: https://forums.swift.org/t/how-to-validate-the-integrity-of-the-docker-images/82916

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions