cdupuis/Docker Sign Attest Verify
Sign, attest and verify attestations
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Maintainedlast commit Jan 31, 2025
- License
- None
Pinned Snippet
uses: cdupuis/dta-workflows@3fb3f4d8bedea1271d2026117c8c9e990adab3a0 # no releases — HEAD as of 2026-07-11tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| stage | Stage of the build | yes | — |
| organization | Namespace of the Docker organization | yes | — |
| image | Image to analyze | yes | — |
| tags | List of tags to add to the attestation | yes | — |
| file | Build file | no | — |
| intoto-statements | in-toto statements | no | — |
| write-comment | suppress writing of comments | no | false |
Outputs
no outputs