Release and supply-chain verification feedback #28
ocularminds
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What evidence do you need before trusting a Decionis Docker artifact in your environment?
The release pipeline publishes multi-platform images with vulnerability gates, provenance, SBOM attestations, and keyless signatures. Share which verification commands, admission controls, registries, or audit exports would make those guarantees easier to consume.
Please distinguish required controls from nice-to-have tooling so maintainers can prioritize the release experience.
All reactions