Verifiable publisher/build identity for an exact PHP Official Image #1687
Madelezhus
started this conversation in
General
Replies: 1 comment 2 replies
|
Can you please say more about the actual problem you're trying to solve? I see a lot of technical details there, but I don't see a real problem statement unless I infer one from between the lines. |
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hello Docker Official Images maintainers,
I am reviewing the provenance of this exact
docker.io/library/phppublication:sha256:f62df9916bc05ae3c5120b41a115938f22623b0c98c815cbe2c67bc73cec21efsha256:450d778f41d54f2f626a3e4e36e8e50e60b08bf370ddc58cb120a28f79283360sha256:19007e4a7829d01a6385be12629c2cd5f5b8a3e1674471f114f56baa90f2aeb1docker-library/php@445bf414f1d5866f7aef715f1203eae043710070, path8.3/trixie/cli/Dockerfile.The metadata digests and provenance subject match. However, I would like to distinguish those integrity checks from authentication of the claimed builder,
https://github.com/docker-library.Is verifiable evidence available linking this exact publication and provenance statement to the authorized Official Images builder or publisher? If so, where can it be obtained, and how should its authority, identity and exact subject be verified? I am not assuming any particular signing technology.
Anonymous Notary requests returned HTTP 401, so access was not obtained. This is not a claim that the image is unsigned.
If another official team handles this question, could you direct me to the appropriate channel?
Thank you.
All reactions