graphprotocol / graphprotocol/graph-node
[Feature] Sign Docker images
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Rust
- Sterne
- 3.2k
- Forks
- 1.1k
- Ø Merge
- 4 T. 1 Std.
- Gemergte PRs (30 T.)
- 1
Beschreibung
Description
To prevent Supply Chain Attacks, the graph-node Docker image should be signed. It's a simple and one-time setup. I've seen you use GCP ecosystem to build and push to Docker Hub. Simply follow the documentation to setup.
More information can be found at the Sigstore documentation.
A whole walk through sigstore and it's cluster policy controller is described in this blog post.
Are you aware of any blockers that must be resolved before implementing this feature? If so, which? Link to any relevant GitHub issues.
No response
Some information to help us out
- Tick this box if you plan on implementing this feature yourself.
- I have searched the issue tracker to make sure this issue is not a duplicate.
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne damit, den auf GCP basierenden Workflow zu finden, der das graph-node Docker-Image erstellt und zu Docker Hub pusht. Lies die verlinkte Dokumentation zu Binary Authorization und Sigstore, um die Einrichtung der Signierung sowie die erforderlichen Anmeldedaten oder die Integration in eine Richtlinie zu bestimmen. Als abgeschlossen gilt die Aufgabe, wenn das veröffentlichte Image signiert ist und seine Signatur verifiziert werden kann.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- docker, gcp
- Bereich
- devops, security
- Issue-Typ
- Feature
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 35/100