-
Sub-task
-
Resolution: Done
-
Critical
-
None
-
None
-
False
-
None
-
False
-
-
-
Builds Sprint #9
Verify that the base images used when building a container image come from a known set of trusted registries to reduce potential supply chain attacks. By default this policy defines trusted registries as registries that are fully maintained by Red Hat and only contain content produced by Red Hat.
solution: Make sure the image used in each task comes from a trusted registry.
msg: Base image "docker.io/library/golang:1.22@sha256:829eff99a4b2abffe68f6a3847337bf6455d69d17e49ec1a97dac78834754bd6"
- clones
-
BUILD-1020 builds components: Use Hermetic Build Mode
- Release Pending
- is cloned by
-
BUILD-1022 builds operator: Build Source Containers
- Release Pending
- links to