Supply chain: signatures, SBOM, CVE scan
Every image the release workflows publish (ghcr.io/infrasagedev/infrasage and ghcr.io/infrasagedev/infrasage-ui) is built, scanned, and only then signed. The steps are in .github/workflows/docker-publish.yml in each repository.
| Step | What you get |
|---|---|
| SBOM | An SPDX SBOM and SLSA provenance attached to the image as attestations (BuildKit), plus sbom.spdx.json kept with the workflow run |
| CVE scan | A Trivy report (critical, high and medium) kept with the run as trivy-report.txt |
| CVE gate | The run fails on any critical CVE that has a fixed version available |
| Signature | A keyless cosign signature. The signer is the workflow's GitHub OIDC identity, logged in the public Rekor transparency log |
An image that fails the gate stays pushed but is not signed. If you enforce signatures, you won't run it.
Verify a signature
cosign verify ghcr.io/infrasagedev/infrasage:0.5.0 \
--certificate-identity-regexp '^https://github.com/sushant-115/infrasage/\.github/workflows/docker-publish\.yml@refs/tags/v' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
For the UI, use infrasage-ui in both the image and the identity. The identity pins the signature to the release workflow running on a version tag, so an image signed from a branch or a fork does not verify.
To enforce this in the cluster, use a policy controller that checks the same identity: Sigstore policy-controller, Kyverno verifyImages, or Connaisseur.
Read the SBOM and provenance
docker buildx imagetools inspect ghcr.io/infrasagedev/infrasage:0.5.0 --format '{{ json .SBOM }}'
docker buildx imagetools inspect ghcr.io/infrasagedev/infrasage:0.5.0 --format '{{ json .Provenance }}'
Mirroring
cosign copy moves an image together with its signature and attestations into your registry:
cosign copy ghcr.io/infrasagedev/infrasage:0.5.0 registry.example.com/infrasage:0.5.0
Verify against the mirror with the same identity flags.
Limits
- Images built before this workflow (0.5.0-rc194 and earlier) are unsigned.
- The gate stops fixable critical CVEs only. Highs and unfixed criticals are in the report, for triage.
- Pilot images built inside the cluster while GitHub Actions was unavailable (
docker.io/library/infrasage:<sha>) are unsigned and never published.