Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Collect hashes of local and remote resources #32

Closed
mikhailswift opened this issue Sep 8, 2021 · 2 comments
Closed

Collect hashes of local and remote resources #32

mikhailswift opened this issue Sep 8, 2021 · 2 comments
Labels
packager sbom Software Bill of Materials

Comments

@mikhailswift
Copy link
Contributor

mikhailswift commented Sep 8, 2021

Currently hashes are being collected for some resources but not all. This should be expanded to include all images, helm charts, files, etc. When resources are fetched from a remote hashes should be confirmed with the remote registry after pull. These hashes should then be verified prior to deploying a zarf package.

This likely will be a sub-task of #22

@jeff-mccoy jeff-mccoy added the sbom Software Bill of Materials label Sep 11, 2021
@RothAndrew RothAndrew added this to the sbom milestone Feb 4, 2022
@jeff-mccoy jeff-mccoy modified the milestones: sbom, Zarf GA Mar 7, 2022
@jeff-mccoy jeff-mccoy added sbom Software Bill of Materials and removed sbom Software Bill of Materials labels Jun 29, 2022
@jeff-mccoy jeff-mccoy removed this from the Zarf GA milestone Jun 29, 2022
@JasonvanBrackel
Copy link
Contributor

Possibly a subtask of #23

@jeff-mccoy
Copy link
Contributor

Stale issue, closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
packager sbom Software Bill of Materials
Projects
None yet
Development

No branches or pull requests

4 participants