Skip to content

feat(cosign): implement cosign for signing docker images in CI #278

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
abhisheksr01 opened this issue Jan 11, 2024 · 0 comments
Open

feat(cosign): implement cosign for signing docker images in CI #278

abhisheksr01 opened this issue Jan 11, 2024 · 0 comments
Assignees
Labels
enhancement New feature or request security-devsecops Security features to improve the security posture and implement DevSecpOps

Comments

@abhisheksr01
Copy link
Owner

abhisheksr01 commented Jan 11, 2024

Description

Implement sigstore/cosign for adding provenance and signing the container image in GitHub Action CI.

Use Case

Once the image is built in the CI and should be signed in the GHA CI.

Proposed Solution

Implement and document the use of cosign in the CI. Document why it's needed.

Benefits

Secure use of container images.

Example

Additional Information

https://github.com/sigstore/cosign

@abhisheksr01 abhisheksr01 added the enhancement New feature or request label Jan 11, 2024
@abhisheksr01 abhisheksr01 self-assigned this Dec 26, 2024
@abhisheksr01 abhisheksr01 added the security-devsecops Security features to improve the security posture and implement DevSecpOps label Dec 26, 2024
@abhisheksr01 abhisheksr01 changed the title Implement Cosign for signing docker images feat)cosing): implement cosign for signing docker images in CI Dec 27, 2024
@abhisheksr01 abhisheksr01 changed the title feat)cosing): implement cosign for signing docker images in CI feat(cosign): implement cosign for signing docker images in CI Dec 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request security-devsecops Security features to improve the security posture and implement DevSecpOps
Projects
None yet
Development

No branches or pull requests

1 participant