Skip to content

Chainguard Images attestation policy is a big OR #9

@mattmoor

Description

@mattmoor

Describe the bug

I believe that these attestations end up being a giant OR:
https://github.com/chainguard-dev/policy-catalog/blob/524be7dc1c401f5cb55644e022add82d43a84925/policies/vendors/chainguard/chainguard-images-attested-cue.yaml

To Reproduce

Find an image that only has one of the specified attestations, and run this on it.

Expected behavior

Any of the missing attestations trigger a failure

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions