You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The signature can be created with GitHub Action and then stored in the container registry.
Quay already supports the sigstore, as it is based on OCI, however only from version 3.6 and quay.io yet wasn't upgraded to this version (but will be).
When the quay.io supports the sigstore we could sign our containers, and ship them signed.
The authentication of the signer is done via the OpenID connect
Investigate, if sigstore can be used for signing the images and if the idea makes sense.
The text was updated successfully, but these errors were encountered: