-
Notifications
You must be signed in to change notification settings - Fork 31
Open
Labels
kind/featureCategorizes issue or PR as related to a new feature.Categorizes issue or PR as related to a new feature.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.Indicates that an issue or PR should not be auto-closed due to staleness.
Description
What would you like to be added:
Our signing library should implement signing of in-toto attestations
Why is this needed:
We need to build our own attestation signing code for three main reasons:
- Signing our provenance attestations during the release process
- Being able to attest of image promoter runs via a signed attestation
- Making sure we can produce general purpose code and tools that other projects in the kubernetes org (and elsewhere) can leverage to generate attestation and build attesting features into other projects.
/kind feature
Metadata
Metadata
Assignees
Labels
kind/featureCategorizes issue or PR as related to a new feature.Categorizes issue or PR as related to a new feature.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.Indicates that an issue or PR should not be auto-closed due to staleness.