Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[QUESTION] add SBOM Attestation to patched images #472

Open
R3DRUN3 opened this issue Jan 15, 2024 · 2 comments
Open

[QUESTION] add SBOM Attestation to patched images #472

R3DRUN3 opened this issue Jan 15, 2024 · 2 comments
Labels
question Further information is requested

Comments

@R3DRUN3
Copy link

R3DRUN3 commented Jan 15, 2024

What is your question?

Is there a way out-of-the-box to attach a Software Bill of Material to patched images, see for example this.
I searched in the docs and in the code but could not find anything.
It will be super usefull, especially when using copa github action.

@R3DRUN3 R3DRUN3 added the question Further information is requested label Jan 15, 2024
@sozercan
Copy link
Member

sozercan commented Jan 16, 2024

@R3DRUN3 not at this time, out of box sbom generation (docker implementation) would require #298

you can generate container sboms with 3rd party tooling such as trivy sbom or syft today though.
there are a few options for attaching secure supply chain artifacts, such as attaching via referrers (used by oras), tags (used by cosign) or part of oci index/manifest list (used by docker)

@R3DRUN3
Copy link
Author

R3DRUN3 commented Jan 17, 2024

@sozercan Thank you!
At present, I have implemented my use case using Syft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
Status: 🆕 New
Development

No branches or pull requests

2 participants