Skip to content

Sign the images with sigstore's fulcio/rekor

Kristian Klausen requested to merge klausenbusk/archlinux-docker:sigstore into master

The ecosystem is moving towards sigstore and we are federated with the public fulcio instance[1], so let's sign our images. Cosign is not used, but the sigstore feature built into podman, which works basically the same way as cosign.

[1] https://github.com/sigstore/fulcio/pull/1214

Fix #77 (closed)

Merge request reports