Skip to content

Sign release images and publish verifiable provenance #173

Description

@Maneek21

The preview ships checksums and an SPDX SBOM, but image signatures and build provenance are not yet documented.

Acceptance criteria:

  • sign release-tagged GHCR images
  • publish provenance from GitHub Actions
  • document verification commands
  • fail the release job if signing or provenance publication fails

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is neededreleaseRelease packaging and lifecyclesecuritySecurity hardening and supply-chain trust

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions