Skip to content

Feature/lab8#1405

Open
raylduk8 wants to merge 2 commits into
inno-devops-labs:mainfrom
raylduk8:feature/lab8
Open

Feature/lab8#1405
raylduk8 wants to merge 2 commits into
inno-devops-labs:mainfrom
raylduk8:feature/lab8

Conversation

@raylduk8

@raylduk8 raylduk8 commented Jul 3, 2026

Copy link
Copy Markdown

Goal

Sign the Juice Shop image with Cosign in a local registry, attach the CycloneDX SBOM from Lab 4 as an attestation

Changes

  • labs/lab8/keys/[cosign.pub](https://vk.com/away.php?to=https%3A%2F%2Fcosign.pub&utf=1)

  • submissions/[lab8.md](https://vk.com/away.php?to=https%3A%2F%2Flab8.md&utf=1)

Testing


Checklist

  • Task 1 — Image signed + tamper demo (both shown)

  • Task 2 — SBOM + provenance attestations attached and verified

  • Bonus — Blob signed + verify-blob success + tamper failure

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant