Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Expose SBOM results from oci-copy task
This is important, because it is how the enterprise contract tooling recognizes that this is an SBOM to be trusted. It won't trust just any SBOM tagged in the registry. It has to be able to find a reference to the SBOM by digest in the provenance record. https://github.com/enterprise-contract/ec-policies/blob/718386d2239dae85a866f6bcd0adbba036cd1b1d/policy/lib/sbom.rego#L26-L34
- Loading branch information