Skip to content

Maintenance update

San 'rdn' Mônico requested to merge feature/cosign-attest into main

This is a maintenance update

Changes

  • Re-add container attestation
    • Using Cosign's attestation over prior Syft attestation
  • Fix cosign v2's --yes in sign and attest commands
  • Add Remark CI job to lint Markdown .md files

Other minor changes

  • Switching to overlay container storage driver (from vfs) for better performance — now supported by newer podman-steroids image
  • Improved SBOM generation in Makefile so they are not phony anymore

PSA

shiftleft.io recently changed name and website to Qwiet.ai, and the next-gen SAST changed to Qwiet.ai preZero which you can see in the Shiftleft.io Documentation page: https://docs.shiftleft.io/home

This is the official announcement of the change: https://qwiet.ai/shiftleft-is-now-qwiet-ai/

For now, their executable next-gen SAST is still being called shiftleft and sl so I will keep them with the current name and format. But I will be watching it closely for other changes to their product, not only name, but also license too.


Signed-off-by: San 'rdn' Mônico <san@monico.com.br>

Edited by San 'rdn' Mônico

Merge request reports