Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[feature] Provide the ability to show/download SBOM/VULN attestations #300

Open
HoustonDad opened this issue Aug 20, 2024 · 0 comments
Open
Labels
enhancement New feature or request priority/review size/L Denotes an issue/PR requiring a relatively large amount of work
Milestone

Comments

@HoustonDad
Copy link

Is this RFE related to an Existing Problem? If so, please describe:
When using Hauler to pull down images from Carbide, those images provide sbom and vulnerability reports in the form of attestations. Currently, if someone wants to view those attestations, they need to download 'cosign' and docker, figure out if the image is single arch or multi-arch, and then use the appropriate cosign commands to show / validate those attestations. Having either a wrapper script or having this functionality built into Hauler would allow customers to not have to use any other tooling.

Describe Proposed Solution(s):
Add functionality to Hauler to download/view those attestations

Describe Possible Alternatives:
Possibly a wrapper script? But that's just another external tool that's needed.

@HoustonDad HoustonDad added the enhancement New feature or request label Aug 20, 2024
@github-project-automation github-project-automation bot moved this to Pending Review in Hauler Aug 20, 2024
@zackbradys zackbradys added size/L Denotes an issue/PR requiring a relatively large amount of work priority/review labels Aug 20, 2024
@zackbradys zackbradys added this to the Hauler v1.3.0 milestone Sep 21, 2024
@zackbradys zackbradys moved this from To Triage to Backlog in Hauler Nov 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request priority/review size/L Denotes an issue/PR requiring a relatively large amount of work
Projects
Status: Backlog
Development

No branches or pull requests

2 participants