Skip to content

Create and Attach the generated SBOM to the Image #229

@Vad1mo

Description

@Vad1mo

Currently, we are signing the images with cosign, we should also attach the generated SBOMs (from goreleasers or otherwise) to the image

here is a guide:
https://aquasecurity.github.io/trivy/v0.56/docs/supply-chain/attestation/sbom/

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions