mutli-arch docker images, such as linux/arm/v7,linux/arm64/v8,linux/arm/v6,linux/amd64,linux/ppc64le,linux/s390x
GNU General Public License v3.0
17
stars
4
forks
source link
Attach SBOM and Provenance attestations to the docker images #7
Open
candrews opened 4 months ago
Attach provenance attestation to the docker images
The provenance attestations include facts about the build process.
See: https://docs.docker.com/build/attestations/slsa-provenance/
Attach sbom attestation to docker images
Software Bill of Materials (SBOM) attestations describe what software artifacts an image contains, and artifacts used to create the image.
See: https://docs.docker.com/build/attestations/sbom/