sigstore / cosign

Code signing and transparency for containers and binaries
Apache License 2.0
4.23k stars 506 forks source link

Reconsider deprecation of SBOM attachments #3685

Closed marklechner closed 2 months ago

marklechner commented 2 months ago

An additional consideration when trying to use syft and cosign with AWS KMS and ECR

marklechner commented 2 months ago

false alarm... seems like cosign attest --predicate some.sbmom --key awskms:xyz actually works