Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sign docker images using docker content trust #9875

Open
RaananHadar opened this issue Mar 21, 2024 · 0 comments
Open

sign docker images using docker content trust #9875

RaananHadar opened this issue Mar 21, 2024 · 0 comments

Comments

@RaananHadar
Copy link
Contributor

What is the goal / desired outcome?
improve pachyderms security and make it less susceptible to supply chain attacks. this will also improve pachyderm’s brand as using docker content trust is considered a good security practice for a serious project using dockerhub.
If there is a way to accomplish this today via workaround, what does that require?
i can build the images manually from source and sign them myself.
(Optional) What is your proposal for a feature to solve this?
implement docker content trust as part of your deployment pipeline.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant