You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We(w/@Dentrax)'ve opened an issue in the Trivy project related to the signing attestation before saving it to the disk.1 A similar work has also been done in the Syft project.2 Thanks to @knqyf263, he came up with an interesting idea, if we pass attestations via a pipe in attest cmd, then all security scanners don't have to re-implement cosign functionalities. So, the UX would be like the following:
Description
We(w/@Dentrax)'ve opened an issue in the Trivy project related to the signing attestation before saving it to the disk.1 A similar work has also been done in the Syft project.2 Thanks to @knqyf263, he came up with an interesting idea, if we pass attestations via a pipe in attest cmd, then all security scanners don't have to re-implement cosign functionalities. So, the UX would be like the following:
This makes a lot of sense to me, so I've raised an issue in Cosign to discuss further; if you like the idea, I'm willing to work on it, thanks.
Footnotes
https://github.com/aquasecurity/trivy/issues/2758 ↩
https://github.com/anchore/syft/pull/785 ↩
The text was updated successfully, but these errors were encountered: