3 ms·
Docker ships with support for image signing, execution authorization (based on trusted signatures), and distribution endpoint authentication (TLS / PKI). Most i
by zerotolerance 8y ago
Docker ships with support for image signing, execution authorization (based on trusted signatures), and distribution endpoint authentication (TLS / PKI). Most image registries offer deep package inspection, OSS package manifests, and CVE visibility.
If all that isn't enough, individual image layers can be accessed and inspected by hand (they're just tar files).
If you're looking for "end-to-end chain of custody" you're going to need to specify the ends. Image signatures get you point-in-stack authorship assertions. I'm not sure what else anyone could ask for here.