AcademySoftwareFoundation / AcademySoftwareFoundation/aswf-docker
Document SHA-256 container image signatures
Open
- Dominant language
- Python
- Stars
- 189
- Forks
- 42
- Avg merge
- 9h 38m
- Merged PRs (30d)
- 6
Description
When a new container image is pushed to Docker Hub, its SHA-256 signature should be easy to find in the repo so that consumers can verify that they are pulling down the container image that was originally built.
Contributor guide
Research direction
Start by locating the repository documentation and the Docker Hub image publishing workflow. Determine where each pushed image's SHA-256 signature should be recorded so consumers can find and verify it; done means the repository clearly exposes the signature for new images.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- devops, documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100