Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: attest build provenance for Docker images #717

Merged
merged 1 commit into from
May 4, 2024

Conversation

sjinks
Copy link
Member

@sjinks sjinks commented May 4, 2024

Artifact attestations enable us to create unfalsifiable provenance and integrity guarantees for the images we build, thus increasing their supply chain security. People who consume our images can verify where and how they were built.

@sjinks sjinks self-assigned this May 4, 2024
@sjinks sjinks requested a review from a team as a code owner May 4, 2024 13:25
@sjinks sjinks force-pushed the add/provenance-attestation branch from cbc6efb to 5413227 Compare May 4, 2024 14:04
Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/dev-tools:0.9 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/alpine:3.19.1 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/traefik_openssl:2.11.2 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/nginx:1.26.0 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/skeleton:latest (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/photon:latest (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:6.3 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:6.4 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:6.2 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:6.1 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:6.0 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:6.5 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.1 (ubuntu 22.04)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/mu-plugins:0.1 (alpine 3.19.1)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.2 (ubuntu 22.04)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/php-fpm:8.3 (ubuntu 22.04)

No vulnerabilities found.

Copy link

github-actions bot commented May 4, 2024

Trivy Scan Report

ghcr.io/automattic/vip-container-images/wordpress:trunk (alpine 3.19.1)

No vulnerabilities found.

@sjinks sjinks merged commit 2b06102 into master May 4, 2024
19 checks passed
@sjinks sjinks deleted the add/provenance-attestation branch May 4, 2024 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant