Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build trillian container to existing release. #715

Merged
merged 1 commit into from
Mar 8, 2022

Conversation

k4leung4
Copy link
Contributor

@k4leung4 k4leung4 commented Mar 7, 2022

Signed-off-by: Kenny Leung kleung@chainguard.dev

Summary

Add Trillian server and signer container as part of Rekor release.
This would provide a multi-platform image that is signed.
The image from github.com/google/trillian also runs the image as root, when it is not necessary.

Once github.com/google/trillian provides signed images and stops running as root, we should consider moving back to using images from them.

Thanks to @nsmith5 for discovering that the image from github.com/google/trillian runs as root.

Ticket Link

Fixes

Release Note


Signed-off-by: Kenny Leung <kleung@chainguard.dev>
@k4leung4 k4leung4 requested a review from cpanato as a code owner March 7, 2022 23:04
@dlorenc dlorenc merged commit ce7f663 into sigstore:main Mar 8, 2022
@github-actions github-actions bot added this to the v1.0.0 milestone Mar 8, 2022
@k4leung4 k4leung4 deleted the rel-trillian branch March 8, 2022 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants