No description
Find a file
gerblesh 2ff118dbdc
feat: add signing module to replace signing.sh (#111)
* feat: signing module

* docs: add docs for `signing` module

* fix(signing.sh): add space to if

Co-authored-by: Gerald Pinder <gmpinder@gmail.com>

* fix(signing): grammar in README and formatting in signing.sh

* fix: only modify image-info.json

* fix: typo in image vendor name

---------

Co-authored-by: Gerald Pinder <gmpinder@gmail.com>
2024-02-03 10:30:01 +00:00
.github chore(deps): bump sigstore/cosign-installer from 3.2.0 to 3.3.0 2023-12-11 15:15:15 +00:00
empty fix: copy empty directory to be missing folders 2024-01-27 18:50:30 +02:00
modules feat: add signing module to replace signing.sh (#111) 2024-02-03 10:30:01 +00:00
Containerfile fix: copy empty directory to be missing folders 2024-01-27 18:50:30 +02:00
cosign.pub chore: add sample files and README 2023-06-25 00:09:55 -03:00
LICENSE Initial commit 2023-06-24 16:38:47 -04:00
README.md docs: update README to reflect current state of repo 2024-01-24 18:31:11 +02:00

bling

build-ublue

This repository containes modules to use in recipe.yml. See list of modules in ./modules

Usage

You can add this to your Containerfile to copy the modules from this image over:

COPY --from=ghcr.io/ublue-os/bling:latest /modules /tmp/modules/

Verification

These images are signed with sisgstore's cosign. You can verify the signature by downloading the cosign.pub key from this repo and running the following command:

cosign verify --key cosign.pub ghcr.io/ublue-os/bling

See what is in this image

Raw commands

NOTE: This makes it so you need to extract everything from the base image!

podman save ghcr.io/ublue-os/bling:latest -o bling.tar
tar xf bling.tar && rm bling.tar
tar xf *.tar

This should extract the image in a way that you can see everything in it!

Using Dive

This method allows you to inspect the image through a TUI

dive ghcr.io/ublue-os/bling:latest