deislabs / image-layer-provenance

Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

We need more examples how the provenance docs look like in the various scenarios

toddysm opened this issue · comments

Providing more examples how the provenance docs look like in various scenarios will be helpful to understand the proposal better. Right now, it is not clear what provenance information will be added for externally imported images and for images that are built internally. Also, how will confidential information be handled in the provenance.