Update github.com/openshift/client-go digest to 35abaf5 #68
must-gather-latest.yml
on: push
must-gather-latest
/
container
1m 2s
must-gather-latest
/
sign
7s
Annotations
3 warnings and 3 notices
must-gather-latest / container
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals:
images/must-gather/Dockerfile.ocp#L6
JSONArgsRecommended: JSON arguments recommended for ENTRYPOINT to prevent unintended behavior related to OS signals
More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/
|
must-gather-latest / sign
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Verify signature
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:77863a54f915fcfbd1a8a1d9897aef63e1d1c88c144cebfa885292ece3cbc63d | jq '.[0]'
|
Inspect signature bundle
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:77863a54f915fcfbd1a8a1d9897aef63e1d1c88c144cebfa885292ece3cbc63d | jq '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson'
|
Inspect certificate
COSIGN_EXPERIMENTAL=1 cosign verify ghcr.io/complianceascode/must-gather-ocp@sha256:77863a54f915fcfbd1a8a1d9897aef63e1d1c88c144cebfa885292ece3cbc63d | jq -r '.[0].optional.Bundle.Payload.body |= @base64d | .[0].optional.Bundle.Payload.body | fromjson | .spec.signature.publicKey.content |= @base64d | .spec.signature.publicKey.content' | openssl x509 -text
|
Artifacts
Produced during runtime
Name | Size | |
---|---|---|
ComplianceAsCode~compliance-operator~C0BA42.dockerbuild
|
44.7 KB |
|