AcademySoftwareFoundation / AcademySoftwareFoundation/aswf-docker

Document SHA-256 container image signatures

Open
#369 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
189
Forks
42
Avg merge
9h 38m
Merged PRs (30d)
6

Description

When a new container image is pushed to Docker Hub, its SHA-256 signature should be easy to find in the repo so that consumers can verify that they are pulling down the container image that was originally built.

Contributor guide

Open the contributing guide

Research direction

Start by locating the repository documentation and the Docker Hub image publishing workflow. Determine where each pushed image's SHA-256 signature should be recorded so consumers can find and verify it; done means the repository clearly exposes the signature for new images.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops, documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.