Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sign official images with sigstore/cosign #562

Open
sudo-bmitch opened this issue Oct 9, 2023 · 5 comments
Open

Sign official images with sigstore/cosign #562

sudo-bmitch opened this issue Oct 9, 2023 · 5 comments
Assignees
Labels
community_new New idea raised by a community contributor trusted_content Docker Official Images, Docker Verified Publishers and Docker Sponsored Open Source requests

Comments

@sudo-bmitch
Copy link

Tell us about your request
It would be helpful to support sigstore/cosign to verify official images from Docker. This could be done in addition to other signing solutions to give users the flexibility to use their own preferred signing solution.

Which service(s) is this request for?
Docker Official Images (DOI).

Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?
Verify the authenticity of official images. This can only be done by Docker.

Are you currently working around the issue?
Using images other than DOI or using DOI images without verifying their authenticity.

Additional context
I'll open similar issues for other signing tools.

@sudo-bmitch sudo-bmitch added the community_new New idea raised by a community contributor label Oct 9, 2023
@sudo-bmitch
Copy link
Author

Linking issues #561 and #563.

@developer-guy
Copy link

developer-guy commented Oct 9, 2023

Related with: #269 cc @Dentrax

@sudo-bmitch
Copy link
Author

duplicates with: #269 cc @Dentrax

@developer-guy I meant to link that one too. I wouldn't say a duplicate, but certainly related. #269 is asking to add signing capabilities to docker build. I'm asking for Docker Official Images to be signed, which could be done by calling cosign in their build pipeline.

@developer-guy
Copy link

I changed that with related, thanks, this is more accurate 👋

@NeilHanlon
Copy link

Heavy +1, as a maintainer of a library image.

@amyb12345 amyb12345 added the trusted_content Docker Official Images, Docker Verified Publishers and Docker Sponsored Open Source requests label Oct 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
community_new New idea raised by a community contributor trusted_content Docker Official Images, Docker Verified Publishers and Docker Sponsored Open Source requests
Projects
None yet
Development

No branches or pull requests

5 participants