-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ci: attest build provenance for Docker images #717
Conversation
cbc6efb
to
5413227
Compare
Trivy Scan Reportghcr.io/automattic/vip-container-images/dev-tools:0.9 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/alpine:3.19.1 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/traefik_openssl:2.11.2 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/nginx:1.26.0 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/skeleton:latest (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/photon:latest (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:6.3 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:6.4 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:6.2 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:6.1 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:6.0 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:6.5 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/php-fpm:8.1 (ubuntu 22.04)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/mu-plugins:0.1 (alpine 3.19.1)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/php-fpm:8.2 (ubuntu 22.04)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/php-fpm:8.3 (ubuntu 22.04)No vulnerabilities found. |
Trivy Scan Reportghcr.io/automattic/vip-container-images/wordpress:trunk (alpine 3.19.1)No vulnerabilities found. |
Artifact attestations enable us to create unfalsifiable provenance and integrity guarantees for the images we build, thus increasing their supply chain security. People who consume our images can verify where and how they were built.