All the Toolbx and Distrobox container images and the ones in my personal namespace on Quay.io are now signed using cosign. How to set this up was not really well documented so this post is an attempt at that. First we will look at how to setup a GitHub workflow using GitHub Actions to build multi-architecture container images with buildah and push them to a registry with podman. Then we will sign those images with cosign (sigstore) and detail what is needed to configure signature validation on the host. Finally we will detail the remaining work needed to be able to do the entire process only with podman.
Everything You Never Wanted to Know About CMake (Redux) izzys.casa - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from izzys.casa Daily Mail and Mail on Sunday newspapers.