Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(ci): Verify base image with cosign before building #211

Merged
merged 2 commits into from
Dec 31, 2023
Merged

Conversation

EyeCantCU
Copy link
Contributor

Validates the integrity of the base image being built from via cosign before continuing to build. Ensures we only build with signed images

@EyeCantCU EyeCantCU requested a review from castrojo as a code owner December 24, 2023 19:10
@xynydev
Copy link
Member

xynydev commented Dec 25, 2023

Why the move of maximize build space?

@EyeCantCU
Copy link
Contributor Author

EyeCantCU commented Dec 27, 2023

Why the move of maximize build space?

It's only something that's beneficial when we begin the build. By moving it, we can get everything else out of the way first. I.E., if we maximize build space and then verify the base image that then fails, we've wasted a fair bit of time and resources for nothing

Will fix this PR momentarily

Validates the integrity of the base image being built from via cosign
before continuing to build. Ensures we only build with signed images
@xynydev xynydev merged commit 52e6a45 into template Dec 31, 2023
2 checks passed
@xynydev xynydev deleted the verify branch December 31, 2023 10:41
elgabo86 referenced this pull request in elgabo86/gablue Dec 31, 2023
feat(ci): Verify base image with cosign before building (#211)
noahdotpy referenced this pull request in noahdotpy/myfedora Jan 5, 2024
* feat(ci): Verify base image with cosign before building

Validates the integrity of the base image being built from via cosign
before continuing to build. Ensures we only build with signed images

* fix(ci): Extract base image name from base image URL for verification
CheariX pushed a commit to CheariX/chearixblue that referenced this pull request Jan 6, 2024
* feat(ci): Verify base image with cosign before building

Validates the integrity of the base image being built from via cosign
before continuing to build. Ensures we only build with signed images

* fix(ci): Extract base image name from base image URL for verification
CheariX pushed a commit to CheariX/chearixblue that referenced this pull request Jan 6, 2024
* feat(ci): Verify base image with cosign before building

Validates the integrity of the base image being built from via cosign
before continuing to build. Ensures we only build with signed images

* fix(ci): Extract base image name from base image URL for verification
Craftidore referenced this pull request in Craftidore/shale Jan 27, 2024
* feat(ci): Verify base image with cosign before building

Validates the integrity of the base image being built from via cosign
before continuing to build. Ensures we only build with signed images

* fix(ci): Extract base image name from base image URL for verification
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants