Skip to content

Published, cosign-signed image with SBOM attestation #19

Description

@stubbi

Publish ghcr.io/paperclipinc/chorus signed with cosign keyless (OIDC) and carrying an SPDX SBOM attestation, per SECURITY.md.

Acceptance: cosign verify pins the signer to the publish workflow and exits 0; the SBOM attestation verifies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:packagingbuild, CI, release, imagessecuritysecurity-sensitive

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions