Batuhan Apaydın
Batuhan Apaydın
Hello, I can take over this one if nobody is interested in it, thanks to @dirien, who has done similar work on Cosign project. https://github.com/sigstore/cosign/issues/2186
Found this. https://github.com/anchore/grype#offline-and-air-gapped-environments
kindly ping @jonjohnsonjr
I think we can store this information in the _annotations_ of the image manifest (which might be verbose) or _labels_ of the image config, as _BuildKit_ did, and read that...
^ @eddycharly
it would be good to release ko v0.13.0 that includes that fix ☝️
we (w/@Dentrax) are the volunteers for doing this issue 🥳🙋🏻♂️🤝
>I prefer the rekor.sigstore.dev URL so that people can easily know which tlog the entry is in. Yeah, that makes sense to me either, but from the end-user perspective, when...
any other thoughts?
>If we really want this maybe we could put this in a separate configurable annotation? 🤔 This would be great if we could! I'm so thrilled to do that 🙈