Skip to main content

Docker Images

Sign Docker images with cosign

Sign your Docker images after they're pushed.

Config

docker_signs:
  - artifacts: all
    cmd: cosign
    args: ["sign", "--key=cosign.key", "${artifact}"]

Docker sign config fields

FieldTypeDefaultDescription
artifactsstringnoneWhat to sign: none, all
cmdstringSigning command
argslistArguments (templates supported)