You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At present, we use an interim solution to make chiseled images scannable. That has worked well. We've been waiting for the chisel manifest format to land to move to a more permanent solution. However, scanners don't support the chisel manifest. We talked to @cjdcordeiro about this. His vision is that SBOM tools (starting with the MS one) support chisel manifests as an input and we rely on scanners ability to read SBOMs.
Our end to end vision is this:
SBOM tools support chisel manifests as an input
We run the SBOM tool to generate an SBOM for the container images we publish
We attach the SBOM to our container images as an OCI artifact
Scanners can scan our container images by pulling by an image and the associated registry artifact
How does that sound? I'm a bit worried that a registry-based solution might be a breaking change for some users. That's worth discussing.
What's the best path to achieving that?
The text was updated successfully, but these errors were encountered:
richlander
changed the title
Support chisel manifest as an sbom input
Support Ubuntu Chisel manifests as an sbom input
Nov 21, 2024
In reference to dotnet/dotnet-docker#5973
We (.NET Team) have been working closely with Canonical on Chiseled images:
At present, we use an interim solution to make chiseled images scannable. That has worked well. We've been waiting for the chisel manifest format to land to move to a more permanent solution. However, scanners don't support the chisel manifest. We talked to @cjdcordeiro about this. His vision is that SBOM tools (starting with the MS one) support chisel manifests as an input and we rely on scanners ability to read SBOMs.
Our end to end vision is this:
How does that sound? I'm a bit worried that a registry-based solution might be a breaking change for some users. That's worth discussing.
What's the best path to achieving that?
The text was updated successfully, but these errors were encountered: