cosign tree
Display supply chain security related artifacts for an image such as signatures, SBOMs and attestations
Options
Name | Description |
---|---|
--output-file <output-file> | Log output to a file |
--timeout, -t <timeout> | Timeout for commands |
--verbose, -d | Log debug output |
--allow-insecure-registry | Whether to allow insecure connections to registries. Don't use this for anything but testing |
--attachment-tag-prefix <attachment-tag-prefix> | Optional custom prefix to use for attached image tags. Attachment images are tagged as: `[AttachmentTagPrefix]sha256-[TargetImageDigest].[AttachmentName]` |
--k8s-keychain | Whether to use the kubernetes keychain instead of the default keychain (supports workload identity) |
--help, -h | Help for tree |