-
Task
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
3
-
False
-
-
False
-
-
All container refs in the index container should use pinned digests.
This includes (but is not limited to):
- catalog entities,
- generated dynamic-plugins.default.yaml
- index.json
If we can use :tag@sha256:digest format like in containerfiles, eg., registry.access.redhat.com/ubi9/go-toolset:9.7-1763038106@sha256:380d6de9bbc5a42ca13d425be99958fb397317664bb8a00e49d464e62cc8566c, great!
If not we can use @sha256:digest format, and provide a nearby comment one line above in the yaml files that exposes the tag for easier legibility.
We could also have comment with the build's timestamp for additional metadata to help support and debugging.
- is cloned by
-
RHIDP-9840 Provide mechanism to filter catalog index content by support level
-
- New
-
-
RHIDP-9842 [catalog index] DUPLICATE all 'dynamic-plugin/dist/' paths with their matching oci:// references, but disabled
-
- Review
-