No description
  • Open Policy Agent 81.4%
  • Go 18.6%
Find a file
tuf-on-ci 506e6f246a Online sign (timestamp)
Signed-off-by: tuf-on-ci <41898282+github-actions[bot]@users.noreply.github.com>
2024-12-03 13:25:18 +00:00
.github Remove ro token stuff now that repo is public 2024-10-23 10:01:09 +01:00
ceremony fix ceremony date 2024-07-02 08:26:41 -05:00
metadata Online sign (timestamp) 2024-12-03 13:25:18 +00:00
targets Signing event: sign/promote-testing-policy-2 (#46) 2024-09-24 10:43:00 +01:00
tools/key-verification feat: remove dependencies 2024-08-14 13:43:14 -05:00
.gitignore chore: update docs and .gitignore 2024-04-16 16:06:46 -05:00
go.mod feat: remove dependencies 2024-08-14 13:43:14 -05:00
LICENSE Update docs, add license (#29) 2024-08-14 13:20:24 -05:00
NOTICE Add notice, update security (#31) 2024-08-14 13:59:48 -05:00
README.md Update docs, add license (#29) 2024-08-14 13:20:24 -05:00
SECURITY.md Add notice, update security (#31) 2024-08-14 13:59:48 -05:00

TUF

Docker's production TUF repository generated using TUF-on-CI.

The TUF metadata can be found in the metadata directory.

The TUF targets can be found under the targets directory. The TUF targets for Docker Official Images (DOI), specifically the policies used to verify DOI, can be found in the targets/doi directory.

Signing Ceremony

The process used to establish Docker's production TUF root is documented in CEREMONY.md.

Keys

Keyholder Name Keyholder GitHub ID Role Serial Number
Jean Laurent jeanlaurent Root 28751288
Alex Hokanson ingshtrom Root 25515142
Brett Inman binman-docker Root 25515991
Christian Dupuis cdupuis Root 25599865
Rachel Taylor rachel-taylor-docker Root 25515264
Laurent Goderre LaurentGoderre Delegated Targets (DOI) 25515985
Tianon Gravi tianon-sso Delegated Targets (DOI) 25515137
Joseph Ferguson yosifkit Delegated Targets (DOI) 25515267
Joel Kamp mrjoelkamp Targets, Delegated Targets (DOI) 25515139
David Dooling whalelines Targets, Delegated Targets (DOI) 25515003
James Carnegie kipz Targets, Delegated Targets (DOI) 28751259
Jonny Stoten jonnystoten Targets, Delegated Targets (DOI) 28751258

Verifying

To verify the TUF root key attestations, see key verification README.

Security reporting

If you have any security concerns please follow SECURITY.md