Better GH Action pipeline for func-utils image#3283
Better GH Action pipeline for func-utils image#3283knative-prow[bot] merged 1 commit intoknative:mainfrom
Conversation
* The image build is reproducible: if the func-utils binary is unchanged so are the images. * Provenance of images using cryptographic signatures. Signed-off-by: Matej Vašek <matejvasek@gmail.com>
|
PTAL @lkingland @gauron99 |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3283 +/- ##
==========================================
- Coverage 54.56% 54.55% -0.02%
==========================================
Files 167 167
Lines 19512 19512
==========================================
- Hits 10647 10645 -2
- Misses 7804 7808 +4
+ Partials 1061 1059 -2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
@lkingland @gauron99 are you admins could you prune all the all packages/images? https://github.com/knative/func/pkgs/container/func-utils/versions |
|
Also plz override the failing check that I did not break. |
lkingland
left a comment
There was a problem hiding this comment.
Great; that's precisely the kind of reproducibility we need to start ensuring a secure image supply chain.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: lkingland, matejvasek The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Changes
The image build is reproducible: if the func-utils binary is unchanged so are the images.
Currently we have too many images that are basically identical but differing in some metadata.
This change will limit this package proliferation.
Provenance of image origin using cryptographic signatures. Probably nobody uses that, but if somebody wanted to verify that the func-utils image originates form the knative org, now they can.