Skip to main content

Supply chain: signatures, SBOM, CVE scan

Every image the release workflows publish (ghcr.io/infrasagedev/infrasage and ghcr.io/infrasagedev/infrasage-ui) is built, scanned, and only then signed. The steps are in .github/workflows/docker-publish.yml in each repository.

StepWhat you get
SBOMAn SPDX SBOM and SLSA provenance attached to the image as attestations (BuildKit), plus sbom.spdx.json kept with the workflow run
CVE scanA Trivy report (critical, high and medium) kept with the run as trivy-report.txt
CVE gateThe run fails on any critical CVE that has a fixed version available
SignatureA keyless cosign signature. The signer is the workflow's GitHub OIDC identity, logged in the public Rekor transparency log

An image that fails the gate stays pushed but is not signed. If you enforce signatures, you won't run it.

Verify a signature​

cosign verify ghcr.io/infrasagedev/infrasage:0.5.0 \
--certificate-identity-regexp '^https://github.com/sushant-115/infrasage/\.github/workflows/docker-publish\.yml@refs/tags/v' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com

For the UI, use infrasage-ui in both the image and the identity. The identity pins the signature to the release workflow running on a version tag, so an image signed from a branch or a fork does not verify.

To enforce this in the cluster, use a policy controller that checks the same identity: Sigstore policy-controller, Kyverno verifyImages, or Connaisseur.

Read the SBOM and provenance​

docker buildx imagetools inspect ghcr.io/infrasagedev/infrasage:0.5.0 --format '{{ json .SBOM }}'
docker buildx imagetools inspect ghcr.io/infrasagedev/infrasage:0.5.0 --format '{{ json .Provenance }}'

Mirroring​

cosign copy moves an image together with its signature and attestations into your registry:

cosign copy ghcr.io/infrasagedev/infrasage:0.5.0 registry.example.com/infrasage:0.5.0

Verify against the mirror with the same identity flags.

Limits​

  • Images built before this workflow (0.5.0-rc194 and earlier) are unsigned.
  • The gate stops fixable critical CVEs only. Highs and unfixed criticals are in the report, for triage.
  • Pilot images built inside the cluster while GitHub Actions was unavailable (docker.io/library/infrasage:<sha>) are unsigned and never published.