ci: cosign keyless sigs, SBOM, provenance + fedora digest pin #7
1 changed files with 2 additions and 0 deletions
2
.github/workflows/build-iso.yml
vendored
2
.github/workflows/build-iso.yml
vendored
|
|
@ -1,3 +1,5 @@
|
|||
# TODO: SHA-pin all uses: tags to commit SHAs (Agent 8 audit recommendation).
|
||||
# Tracked separately so this PR can land without long web lookups.
|
||||
name: Build veilor-os ISO
|
||||
|
||||
on:
|
||||
|
|
|
|||
Loading…
Reference in a new issue