containers / containers/containerimage-py

Develop capability to cryptographically sign and verify images

Open
#45 1 comment 0 reactions 1 assignee Claimed by @whatsacomputertho View on GitHub
v1.1.0
Dominant language
Python
Stars
8
Forks
2
PR merge metrics
No merged PRs in 30d

Description

## Overview

We are working on the ability to copy images between registries, and to/from the filesystem.
- https://github.com/containers/containerimage-py/issues/12
- https://github.com/containers/containerimage-py/issues/44

That would effectively serve as a python-native implementation of the `skopeo copy` command across combinations of the `dir:` and `docker://` transports.

This issue will then track the implementation of a python-native implementation of...
- The `skopeo standalone-sign` and `skopeo standalone-verify` subcommands, in which the images are assumed to be on the filesystem
- The `skopeo copy --sign-by` option, in which the image is being copied from registry to registry

## Acceptance

- [ ] It is possible to cryptographically sign an image on the filesystem using `containerimage-py`
- [ ] It is possible to cryptographically verify an image signature on the filesystem using `containerimage-py`
- [ ] It is possible to cryptographically sign an image while copying it using `containerimage-py`
- [ ] The usage of these new capabilities are documented
- [ ] Example scripts are written for these new capabilities
- [ ] There is unit test coverage for these new capabilities

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.