cdupuis/Docker Sign Attest Verify

Sign, attest and verify attestations

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Jan 31, 2025
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: cdupuis/dta-workflows@3fb3f4d8bedea1271d2026117c8c9e990adab3a0 # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
stageStage of the buildyes
organizationNamespace of the Docker organizationyes
imageImage to analyzeyes
tagsList of tags to add to the attestationyes
fileBuild fileno
intoto-statementsin-toto statementsno
write-commentsuppress writing of commentsnofalse

no outputs