ci.docker icon indicating copy to clipboard operation
ci.docker copied to clipboard

21.0.0.* docker images do not have signed tags

Open nicolashenry opened this issue 4 years ago • 0 comments

Hello,

It seems that 21.0.0.* docker images do not have signed tags like it was the case for 20.0.0.* images:

$ docker trust inspect websphere-liberty:21.0.0.6-kernel-java11-openj9
[
    {
        "Name": "websphere-liberty:21.0.0.6-kernel-java11-openj9",
        "SignedTags": [],
        "Signers": [],
        "AdministrativeKeys": [
            {
                "Name": "Root",
                "Keys": [
                    {
                        "ID": "926f8841cb4536d7cdf5da58e8da340b1ab78f321625bf83570635ce2a61079c"
                    }
                ]
            },
            {
                "Name": "Repository",
                "Keys": [
                    {
                        "ID": "87f6573805d16b95c200735bbe0a708166d91d3a545144466ce6c76cf4aca48f"
                    }
                ]
            }
        ]
    }
]
$ docker trust inspect websphere-liberty:20.0.0.12-kernel-java11-openj9
[
    {
        "Name": "websphere-liberty:20.0.0.12-kernel-java11-openj9",
        "SignedTags": [
            {
                "SignedTag": "20.0.0.12-kernel-java11-openj9",
                "Digest": "f3127642f014ddaf7f28b175061b03b1fd6fa43501e3264fb032f6a4c0f69f8a",  
                "Signers": [
                    "Repo Admin"
                ]
            }
        ],
        "Signers": [],
        "AdministrativeKeys": [
            {
                "Name": "Root",
                "Keys": [
                    {
                        "ID": "926f8841cb4536d7cdf5da58e8da340b1ab78f321625bf83570635ce2a61079c"
                    }
                ]
            },
            {
                "Name": "Repository",
                "Keys": [
                    {
                        "ID": "87f6573805d16b95c200735bbe0a708166d91d3a545144466ce6c76cf4aca48f"
                    }
                ]
            }
        ]
    }
]

Is it possible that you add the missing signed tags? Because it prevent us to use the docker --disable-content-trust=false option.

nicolashenry avatar Jul 05 '21 13:07 nicolashenry