nais/attest-sign
Generate SBOM, attest and sign docker image
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| image_ref | 'form <image>@<digest>' 'image ref, i.e. "europe-north1-docker.pkg.dev/nais-io/nais/images/canary-deployer@sha256:eac1f85bee008dfe4ca0eadd1f32256946a171b445d129dba8f00cc67d43582b"' | yes | — |
| sbom | existing SBOM in cyclonedx format | — | auto-generate-for-me-please.json |
| additional_sboms | newline-separated list of extra CycloneDX SBOM files to merge with the primary SBOM | — | "" |
| trivy_java_db_repositories | specify the --java-db-repository strings for Trivy | — | europe-north1-docker.pkg.dev/nais-io/github-ptc/aquasecurity/trivy-java-db:1,public.ecr.aws/aquasecurity/trivy-java-db,ghcr.io/aquasecurity/trivy-java-db:1 |
Outputs
| name | description |
|---|---|
| sbom | SBOM.json in cyclonedx format |