Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore missing SBOM for Image Indexes #1211

Merged
merged 1 commit into from
Oct 31, 2024
Merged

Conversation

lcarva
Copy link
Member

@lcarva lcarva commented Oct 31, 2024

Currently, Konflux does not create an SBOM for Image Indexes: https://issues.redhat.com/browse/KONFLUX-4330

Until then, do not trigger a violation when an SBOM is not found for such images.

Today, it's not possible to determine if the image being validated is an Image Index or an Image Manifest, see
enterprise-contract/ec-cli#2121. The Image Index detection is done via Konflux-specific heuristics as a workaround.

Currently, Konflux does not create an SBOM for Image Indexes:
https://issues.redhat.com/browse/KONFLUX-4330

Until then, do not trigger a violation when an SBOM is not found for
such images.

Today, it's not possible to determine if the image being validated is an
Image Index or an Image Manifest, see
enterprise-contract/ec-cli#2121. The Image
Index detection is done via Konflux-specific heuristics as a workaround.

Fixes enterprise-contract#1210
Resolves: EC-996

Signed-off-by: Luiz Carvalho <[email protected]>
@lcarva lcarva merged commit 09e1dd5 into enterprise-contract:main Oct 31, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants