Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Definition of a container image label #162

Open
1 task
wurstbrot opened this issue Feb 1, 2025 · 1 comment
Open
1 task

Definition of a container image label #162

wurstbrot opened this issue Feb 1, 2025 · 1 comment

Comments

@wurstbrot
Copy link

wurstbrot commented Feb 1, 2025

💡 Summary

Add a definition of a container image label

Motivation and context

In a quality gate, I want to check if an image is passing predefined checks before it is going to be deployed.
One rudimentary check could be, if CSAF is available for that image/organisation. CSAF so far is using for example /.well-known/security.txt to point out where to find provider-metadata.json.

Implementation notes

Defining a container image label, e.g. org.oasis-open.csaf.provider-metadata with a URL pointing to a provider-metadata.json would be great. This does not check the quality, but would be a first step.

Acceptance criteria

How do we know when this work is done?

  • Image label is defined
@tschmidtb51
Copy link

tschmidtb51 commented Feb 7, 2025

I guess that is something for the CSAF TC to decide. Please formally comment on their comment mailing list: https://groups.oasis-open.org/communities/community-home?CommunityKey=3720cda2-3056-4183-a759-018f5aa7b5f2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants