cosign help attach sbom
Attach sbom to the supplied container image
Options
Name | Description |
---|---|
--output-file <output-file> | Log output to a file |
--timeout, -t <timeout> | Timeout for commands |
--verbose, -d | Log debug output |
--allow-insecure-registry | Whether to allow insecure connections to registries. Don't use this for anything but testing |
--attachment-tag-prefix <attachment-tag-prefix> | Optional custom prefix to use for attached image tags. Attachment images are tagged as: `[AttachmentTagPrefix]sha256-[TargetImageDigest].[AttachmentName]` |
--k8s-keychain | Whether to use the kubernetes keychain instead of the default keychain (supports workload identity) |
--sbom <sbom> | Path to the sbom, or {-} for stdin |
--type <type> | Type of sbom (spdx|cyclonedx|syft) |
--help, -h | Help for sbom |