kubernetes / kubernetes/release
Add rpms and debs to provenance attestation and SBOM
- Dominant language
- Go
- Stars
- 504
- Forks
- 556
- Avg merge
- 18h 43m
- Merged PRs (30d)
- 33
Description
#### What would you like to be added:
We are now building the RPMs and debs as part of the release process. We should be recording these files in the provenance attestation on staging and accounting for them on the final SBOM after they're signed. We should also try to create an attestation of the OBS build if possible and record the packages there too.
#### Why is this needed:
Currently we don;t have a record of these files in our build metadata.
Contributor guide
Research direction
Start by tracing the release process that builds the RPMs and debs, then locate the existing provenance attestation and final SBOM generation. Done means signed packages appear in the staging attestation and final SBOM, with an OBS build attestation and package records added if feasible.
Written by the indexing model from the issue text.
Assessment
- Domain
- build-system, release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100