Replies: 1 comment 1 reply
-
That looks slick @MindTooth but let's hold on this for now - we haven't had any requests for it and I don't have the bandwidth to learn it lately. :-) Still I like the idea of signed/official containers. I'm happy that pwpush has been growing in popularity but I'm struggling a bit to keep up over the last month. Can we revisit this in a few months? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We should look into signing the container images using cosign: https://github.com/sigstore/cosign
I've now testing myself using https://github.com/sigstore/cosign-installer inside a pipeline and it seems to work okay. I just need to get the hang of it a bit more.
Is that something that I should look closer on how to implement for pwpush?
Example project: https://github.com/MindTooth/cosign-test/
Valid signature:
Beta Was this translation helpful? Give feedback.
All reactions