Skip to content

Conversation

@tonistiigi
Copy link
Member

Add an option to use signed cache with Github backend. Signing needs to happen by an external program set in the toml config (eg. cosign via github OIDC) and is verified against the policy specified in the toml config. This allows reusable workflow running in Github actions environment to ensure that cache can not be modified outside of the workflow, even if full access to cache storage is available.

ref docker/github-builder-experimental#56

@tonistiigi tonistiigi requested a review from crazy-max December 6, 2025 19:07
@github-actions github-actions bot added area/dependencies Pull requests that update a dependency file area/buildkitd area/remotecache labels Dec 6, 2025
Signed-off-by: Tonis Tiigi <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant