Open
Description
Describe the problem/challenge you have
would like to verify downloaded contents with https://github.com/sigstore/cosign:
- imgpkg bundle
- pass down image digest
- OCI image (downloaded via imgpkg)
- pass down image digest
- github release assets (see example of https://github.com/sigstore/rekor/releases/tag/v0.3.0)
- http file
- sig files included in archive?
Vote on this request
This is an invitation to the community to vote on issues, to help us prioritize our backlog. Use the "smiley face" up to the right of this comment to vote.
👍 "I would like to see this addressed as soon as possible"
👎 "There are other more important things to focus on right now"
We are also happy to receive and review Pull Requests if you want to help working on this issue.
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Unprioritized