Skip to content
This repository has been archived by the owner on Jan 3, 2023. It is now read-only.

When pushing SPC openscap-daemon Docker images to Docker hub, please sign them #82

Open
iankko opened this issue Apr 25, 2016 · 1 comment

Comments

@iankko
Copy link

iankko commented Apr 25, 2016

Docker starting from 1.8 introduced concept of Docker Content Trust (The Update Framework):

which allows images to be signed when publishing to Docker hub. The consumers can later verify the producer of these images (prevent also image forgery, image replay attacks etc.)

We should start using this functionality when creating openscap/openscap-daemon-* SPC containers:

This is more RFE, than a real bug.

@jan-cerny
Copy link
Member

I suggest closing this ticket as we don't publish SPCs on Docker Hub anymore, instead there is a container in Red Hat Registry.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants