Skip to content

[DEVOPS-4325] ci: add cosign and provenance to docker image#40

Merged
Richard Boisvert (rbstp) merged 1 commit intomasterfrom
devops/cosign
Mar 10, 2026
Merged

[DEVOPS-4325] ci: add cosign and provenance to docker image#40
Richard Boisvert (rbstp) merged 1 commit intomasterfrom
devops/cosign

Conversation

@rbstp
Copy link
Contributor

Summary

  • Upgrade to docker/build-push-action@v6 and add docker/setup-buildx-action@v3
  • Add SLSA provenance (provenance: mode=max) and SBOM attestation (sbom: true)
  • Add Cosign image signing using sigstore/cosign-installer@v3.8.0 (Cosign v2.4.1)

@rbstp Richard Boisvert (rbstp) requested a review from a team as a code owner March 10, 2026 02:34
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Batch approved: DEVOPS-4325 cosign and provenance rollout across repos.

@rbstp Richard Boisvert (rbstp) merged commit 9915d10 into master Mar 10, 2026
1 check failed
@rbstp Richard Boisvert (rbstp) deleted the devops/cosign branch March 10, 2026 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants