brigadecore / brigadecore/kind-node

Scan images, generate SBOMs, sign images

Open
#21 0 comments 0 reactions 1 assignee Claimed by @krancour View on GitHub
security
Dominant language
TypeScript
Stars
0
Forks
2
PR merge metrics
No merged PRs in 30d

Description

For Brigade itself and all its peripherals, we're now scanning images for vulnerabilities as part of CI, generating and publishing SBOMs as part of the release process, and also signing our images.

Now that that's been attended to, it's time to move the security conversation farther back in our stack and apply those learnings to the images we regard as tools or a means to an end.

This issue calls for scanning images during CI, generating and publishing SBOMs during release, and signing images.

The pattern for these things is well established by now and I think can reasonably be handled in a single PR.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.