An image to automatically update and publish Docker images by comparing SBOM changes
10K+
A toolkit to automatically sign, update and publish Docker images. It contains a reusable GitLab CI component and a specific Docker image with useful tools:
The image is also automatically signed, updated and published:
Docker latest tag is 29.8.2-001, 29.8, 29.
The complete software bill of materials (SBOM) of each published image, with its known vulnerabilities,
is collected in the sbom-docker repository, under the
component image-factory.
Dockerhub Overview page has the details of the last published image.
Every publication pushes four tags pointing to the same image digest:
<docker_version>-<increment> Example: 29.6.2-003
<docker_major>.<docker_minor> Example: 29.6
<docker_major> Example: 29
latest
The increment differentiates builds sharing the same Docker version.
Cosign public key:
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEa3yV6+yd/l4zh/tfT6Tx+zn0dhy3
BhFqSad1norLeKSCN2MILv4fZ9GA6ODOlJOw+7vzUvzZVr9IXnxEdjoWJw==
-----END PUBLIC KEY-----
The public key is also available online: https://gitlab.com/op_so/docker/cosign-public-key/-/raw/main/cosign.pub.
To verify an image:
cosign verify --key cosign.pub $IMAGE_URI
To verify and get the SBOM attestation:
cosign verify-attestation --key cosign.pub --type spdxjson $IMAGE_URI | jq '.payload | @base64d | fromjson | .predicate'
This program is free software: you can redistribute it and/or modify it under the terms of the MIT License (MIT). See the LICENSE for details.
Content type
Image
Digest
sha256:456a1cc73…
Size
224.1 MB
Last updated
4 days ago
docker pull jfxs/image-factory