kubernetes / kubernetes/release

Add rpms and debs to provenance attestation and SBOM

Open
#3,065 20 comments 1 reaction 0 assignees View on GitHub
area/release-eng kind/feature lifecycle/frozen needs-priority sig/release
Dominant language
Go
Stars
504
Forks
556
Avg merge
18h 43m
Merged PRs (30d)
33

Description

#### What would you like to be added:

We are now building the RPMs and debs as part of the release process. We should be recording these files in the provenance attestation on staging and accounting for them on the final SBOM after they're signed. We should also try to create an attestation of the OBS build if possible and record the packages there too.

#### Why is this needed:

Currently we don;t have a record of these files in our build metadata.

Contributor guide

Open the contributing guide

Research direction

Start by tracing the release process that builds the RPMs and debs, then locate the existing provenance attestation and final SBOM generation. Done means signed packages appear in the staging attestation and final SBOM, with an OBS build attestation and package records added if feasible.

Written by the indexing model from the issue text.

Assessment

Domain
build-system, release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.