Uploaded image for project: 'Red Hat Internal Developer Platform'
  1. Red Hat Internal Developer Platform
  2. RHIDP-9839

Use digest pinning (and comments with tags for clarity) in catalog entities, index.json and generated dynamic-plugins.default.yaml

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Normal Normal
    • 1.9.0
    • None
    • Build, Catalog, Marketplace
    • None

      All container refs in the index container should use pinned digests.

      This includes (but is not limited to):

      • catalog entities,
      • generated dynamic-plugins.default.yaml
      • index.json

      If we can use :tag@sha256:digest format like in containerfiles, eg., registry.access.redhat.com/ubi9/go-toolset:9.7-1763038106@sha256:380d6de9bbc5a42ca13d425be99958fb397317664bb8a00e49d464e62cc8566c, great!

      If not we can use @sha256:digest format, and provide a nearby comment one line above in the yaml files that exposes the tag for easier legibility.

      We could also have comment with the build's timestamp for additional metadata to help support and debugging.

              Unassigned Unassigned
              nickboldt Nick Boldt
              RHIDP - Cope
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated: