Skip to content

scan-sbom: emit a vulnerability attestation for hardened images #148

Description

@toddysm

Part of #146. Depends on the same predicate/statement shape as the scan-image
child.

Extend the scan-sbom composite action (hardened / distroless path) to emit a
vulnerability attestation over the SBOM-based scan.

Tasks

  • Produce a cosign-vuln-based in-toto Statement for the image from the unioned
    per-platform findings (or per platform, mirroring how SBOM/provenance
    referrers are attached per platform — decide and document).
  • Add an attestation-path output analogous to scan-image.

Notes

  • Reuse the existing per-platform extraction loop.
  • No gate/decision changes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    catalogRelated to the Catalog stagefeatureNew feature or requestobservabilityRelated to Observability

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions