cloudnative-pg / cloudnative-pg/postgres-containers
Cosign architecture-specific images too?
- Lingua principale
- HCL
- Stelle
- 154
- Fork
- 64
- Merge medio
- 4g 12h
- PR unite (30g)
- 9
Descrizione
If I `regctl image copy --referrers ghcr.io/cloudnative-pg/postgresql:18.4-standard-trixie private.goharbor.instance.com/cloudnative-pg/image:18.4`, the top level view appears like this with a green checkmark:
but if I click the "view this OCI index's artifact list" I get this:
so the architecture-specific images aren't signed. This means I can't enable the feature in Harbor that prevents downloads of non-cosigned images since the images from this repository aren't signed recursively.
Is there a reason only the top manifest is signed, or would it be possible to add `--recursive` to the `cosign sign` command that produces the release images in this organization?
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Cerca la configurazione di release che esegue il comando `cosign sign` per le immagini PostgreSQL e verifica come vengono gestiti gli indici multiarchitettura. Verifica l’elenco risultante degli artefatti OCI in Harbor, inclusa ogni immagine specifica per architettura, e conferma che il workflow di release continui a essere completato correttamente.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- docker, postgresql
- Ambito
- devops, release, security
- Tipo di issue
- Funzionalità
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Tranquilla
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 48/100