Sign the images with sigstore's fulcio/rekor
The ecosystem is moving towards sigstore and we are federated with the public fulcio instance[1], so let's sign our images. Cosign is not used, but the sigstore feature built into podman, which works basically the same way as cosign.
[1] https://github.com/sigstore/fulcio/pull/1214
Fix #77 (closed)
Merge request reports
Activity
added 1 commit
- 898ffc0e - Sign the images with sigstore's fulcio/rekor
added 14 commits
-
898ffc0e...3be9448d - 13 commits from branch
archlinux:master
- 8317be4d - Sign the images with sigstore's fulcio/rekor
-
898ffc0e...3be9448d - 13 commits from branch
enabled an automatic merge when the pipeline for 6090c652 succeeds
mentioned in commit 9bbf04ea
mentioned in commit 918175fc
mentioned in commit a3749480
mentioned in merge request !80 (merged)
mentioned in merge request infrastructure!508 (closed)