ChainSafe / ChainSafe/lodestar
Build provenance and SBOM attestations for images
Open
scope-security
- Dominant language
- TypeScript
- Stars
- 1.4k
- Forks
- 483
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 150
Description
Should consider adding this, right now there isn't a good way to verify the code you are running hasn't been tempered with when using a docker image.
See https://github.com/serenita-org/vero/pull/224
Contributor guide
Assessment
This issue has not been assessed yet.