To securely support fetching of attestations by tag we need to add signatures to the uploaded blobs.
- «repository»:«optional-prefix»-«version».sbom
- «repository»:«optional-prefix»-«version».provenance
- «repository»:«optional-prefix»-«version».discovery
This also requires a change in:
Also don't forget to bump README.md docs.
To securely support fetching of attestations by tag we need to add signatures to the uploaded blobs.
This also requires a change in:
Also don't forget to bump README.md docs.