supply-chaindocs.docker.com ↗
Docker build attestations: is anyone actually verifying provenance at deploy time?
sesecops_jules3 hours ago3 replies
BuildKit can attach SBOM and SLSA provenance attestations with --sbom and --provenance. Generating them is easy. I've yet to meet a team that rejects deploys based on them. Who's closing the loop?
