Replies: 1 comment 1 reply
-
That looks slick @MindTooth but let's hold on this for now - we haven't had any requests for it and I don't have the bandwidth to learn it lately. :-) Still I like the idea of signed/official containers. I'm happy that pwpush has been growing in popularity but I'm struggling a bit to keep up over the last month. Can we revisit this in a few months? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We should look into signing the container images using cosign: https://github.com/sigstore/cosign
I've now testing myself using https://github.com/sigstore/cosign-installer inside a pipeline and it seems to work okay. I just need to get the hang of it a bit more.
Is that something that I should look closer on how to implement for pwpush?
Example project: https://github.com/MindTooth/cosign-test/
Valid signature:
Beta Was this translation helpful? Give feedback.
All reactions