Sign inSign up

reytans/demo-build-dockerhub

By reytans

•Updated 2 days ago

Image
0

3.0K

reytans/demo-build-dockerhub repository overview

⁠demo-build-dockerhub

Dumb demo to demonstrate automatic build with

  • Go lang compilation & test on every related push
  • Docker image building (including go compilation inside Dockerfile) on every new tag
  • CI with GitHub Actions & Buildjet with push to ghcr.io/srnfr/demo-build-dockerhub:latest⁠
  • Asynchronous build with DockerHub registry triggered by Web Hook

Cosign⁠ signature added.

SBOM attachment added.

In order to :

a) check the image's signature :

cosign verify --key cosign.pub ghcr.io/srnfr/demo-build-dockerhub:latest

b) download the SBOM :

cosign download sbom ghcr.io/srnfr/demo-build-dockerhub --output-file monsbom.sbom

Then, analyze the vulns with grype⁠ :

grype monsbom.sbom

Tip: use the cosign Docker image (rather than the complex install) :

a) Verify the image's signature

docker run gcr.io/projectsigstore/cosign verify --key https://raw.githubusercontent.com/srnfr/demo-build-dockerhub/master/cosign.pub ghcr.io/srnfr/demo-build-dockerhub:latest

b) Download the Attestation

VER="v119"; docker run gcr.io/projectsigstore/cosign verify-attestation ghcr.io/srnfr/demo-build-dockerhub:${VER} --key https://raw.githubusercontent.com/srnfr/demo-build-dockerhub/master/cosign.pub --type spdx > attestation.json

c) Extract the SBOM from attestation

jq -r '.payload' attestation.json | base64 -d | jq -r '.predicate' > sbom-spdx.json

d) Install grype

curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin

e) Run

grype ./sbom-spdx.json

or

trivy sbom ./sbom-spdx.json 

Tag summary

Content type

Image

Digest

sha256:26d3cd036…

Size

102.1 MB

Last updated

2 days ago

docker pull reytans/demo-build-dockerhub:v125