keptn / lifecycle-toolkit

Toolkit for cloud-native application lifecycle management
https://keptn.sh
Apache License 2.0
280 stars 113 forks source link

Generate and attest provenance for images #3310

Open rakshitgondwal opened 4 months ago

rakshitgondwal commented 4 months ago

Goal

Generate and Attest Provenance for our images using docker/build-push-action.

Details

It will be good to generate and attest provenance for the images being. This can be easily done via the build action that we are currently using docker/build-push-action.

References

https://docs.docker.com/build/ci/github-actions/attestations/

DoD

prakrit55 commented 3 months ago

hii @rakshitgondwal, I wd like to do it

rakshitgondwal commented 3 months ago

Sure, go ahead @prakrit55