Kritis currently (as of v.0.2.2) supports only digest-styled tags, formatted like quay.io/verygoodsecurity/software@sha256:sha256string
FluxCD currently supports only "classic" tags, formatted like quay.io/verygoodsecurity/software:version
A sidecar reverse proxy for Kritis, resolving tags through Docker Hub or Quay.
docker build -t tag_resolver_proxy .
docker run -it tag_resolver_proxy --help
make test
Before checking against Grafeas attestations API, this proxy verifies the following:
- latest tag is not used