You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
it can now pull all the materials in that provenance and verify them offline if it wants to
it issues a rebuild with a special policy that doesn’t allow any outside images or new materials not in the policy. It can also drop the network completely.
it checks if it got the same artifact digest
if it did, then it issues a new (signed) attestation, confirming that our provenance was correct and is based only on our strictly defined sources
our image is now more trustworthy because trusted parties not related to us have verified it. It is impossible it was built from a a different Git commit or used apk package with a CVE for example.
Originally posted by @tonistiigi in #4238 (comment)
The text was updated successfully, but these errors were encountered: