Posts tagged #supply-chain
-
Runner-image supply chain: how to verify the image your CI runs on
A runner image executes your code, so trust in it must be verifiable, not taken on faith. We break down the chain — digest pins, a trivy CVE gate, cosign keyless signing (Sigstore), an SBOM (SPDX and CycloneDX) and SLSA provenance — and how to verify all of it yourself for tempus.build images.