You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Raised while responding to CNCF TAG-Security review of the security self-assessment (cncf/toc#2286), which records "No formal SBOM" as a gap.
Why SBOM is currently disabled β and why it is not simply a flag to flip
.github/workflows/docker.yml sets provenance: false / sbom: false in four places (:295,346,631,818). This is not a deprioritization of supply-chain metadata. It is the fix for #3760 (closed): build-push-action attaches attestations by default, an attestation can only be carried by an OCI image index, and that index form let a COPY --from layer ship an overlayfs metacopy redirect for /usr/local/bin/hive β which containerd/k3s and rootless podman present as non-executable, crash-looping the image.
Re-enabling the flags would reintroduce a shipped-image crash loop. The workflow comments document this at length.
Proposal: generate the SBOM out-of-band
Decouple SBOM generation from the image build so the published manifest stays a plain image:
Add a post-build job running anchore/sbom-action (syft) or aquasecurity/trivy-action against the built image.
Publish the SBOM (SPDX or CycloneDX) as a release asset and/or workflow artifact β not as an OCI attestation.
Optionally sign it with cosign as a detached signature, again avoiding the index form.
Raised while responding to CNCF TAG-Security review of the security self-assessment (cncf/toc#2286), which records "No formal SBOM" as a gap.
Why SBOM is currently disabled β and why it is not simply a flag to flip
.github/workflows/docker.ymlsetsprovenance: false/sbom: falsein four places (:295,346,631,818). This is not a deprioritization of supply-chain metadata. It is the fix for #3760 (closed):build-push-actionattaches attestations by default, an attestation can only be carried by an OCI image index, and that index form let aCOPY --fromlayer ship an overlayfs metacopy redirect for/usr/local/bin/hiveβ which containerd/k3s and rootless podman present as non-executable, crash-looping the image.Re-enabling the flags would reintroduce a shipped-image crash loop. The workflow comments document this at length.
Proposal: generate the SBOM out-of-band
Decouple SBOM generation from the image build so the published manifest stays a plain image:
anchore/sbom-action(syft) oraquasecurity/trivy-actionagainst the built image.application/vnd.oci.image.manifest.v1+jsonand not...index.v1+json, so a future well-meaning change cannot silently reintroduce stable/candidate/edge images: hive binary fails exec with EPERM from /usr/local/bin/hive (works when copied elsewhere)Β #3760.Step 4 matters as much as the SBOM itself β it converts a comment-documented constraint into an enforced one.
Done when
security-self-assessment.mdMetadata row records where to find the SBOM