Skip to content

Sign container images with cosign for supply-chain security #2455

@goelakash

Description

@goelakash

The OpenSSF Scorecard flags the Signed-Releases check because published Docker images are not cryptographically signed.

Signing images with cosign (keyless, via GitHub OIDC) would allow consumers to verify image provenance (e.g. Chainguard Images uses sigstore/cosign-installer in their release workflow).

Related to #2428

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions