Skip to content

Conversation

sudo-bmitch
Copy link
Contributor

@sudo-bmitch sudo-bmitch commented Jul 26, 2025

Fixes issue

Describe the change

Update to SLSA v1 provenance in buildkit. See moby/buildkit#6005 for more details.

How to verify it

After merging and GHA finishes, with a buildkit version of 0.23 or greater, the following should now show a full SLSA v1 attestation:

regctl artifact get --platform local --filter-artifact-type application/vnd.docker.attestation.manifest.v1+json --subject ghcr.io/regclient/regctl:edge

Note, the current buildkit version in GHA is still v0.22.0.

Changelog text

  • Chore: Update to SLSA v1 provenance.

Please verify and check that the pull request fulfills the following requirements

  • Tests have been added or not applicable
  • Documentation has been added, updated, or not applicable
  • Changes have been rebased to main
  • Multiple commits to the same code have been squashed

moby/buildkit#6005
Signed-off-by: Brandon Mitchell <git@bmitch.net>
@sudo-bmitch sudo-bmitch merged commit 9617dee into regclient:main Jul 26, 2025
4 checks passed
@sudo-bmitch sudo-bmitch deleted the pr-provenance-slsa-v1 branch July 26, 2025 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant