goharbor / harbor-cli

[Sandbox] Official Harbor CLI
Apache License 2.0
42 stars 45 forks source link

Create and Attach the generated SBOM to the Image #229

Open Vad1mo opened 3 weeks ago

Vad1mo commented 3 weeks ago

Currently, we are signing the images with cosign, we should also attach the generated SBOMs (from goreleasers or otherwise) to the image

here is a guide: https://aquasecurity.github.io/trivy/v0.56/docs/supply-chain/attestation/sbom/