Skip to content

Security

Reporting a vulnerability

Please use the project's private vulnerability reporting feature to report any vulnerabilities. For more information, see https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability.

Only the most recent major version is regularly updated and receives security fixes.

Image signature and provenance verification

Prerequisites:

  • cosign
  • GitHub CLI, logged in to any GitHub account (gh auth login) - it fetches the provenance from GitHub's attestations API
  • crane

All released container images are signed using cosign and SLSA Level 3 provenance is available for verification.

IMAGE=ghcr.io/miracum/vfps:v1.22.4
DIGEST=$(crane digest "${IMAGE}")
IMAGE_DIGEST_PINNED="ghcr.io/miracum/vfps@${DIGEST}"
IMAGE_TAG="${IMAGE#*:}"

cosign verify \
   --certificate-oidc-issuer=https://token.actions.githubusercontent.com \
   --certificate-identity-regexp="https://github.com/miracum/.github/.github/workflows/standard-build.yaml@.*" \
   --certificate-github-workflow-name="ci" \
   --certificate-github-workflow-repository="miracum/vfps" \
   --certificate-github-workflow-trigger="release" \
   --certificate-github-workflow-ref="refs/tags/${IMAGE_TAG}" \
   "${IMAGE_DIGEST_PINNED}"

gh attestation verify "oci://${IMAGE_DIGEST_PINNED}" \
   --repo miracum/vfps \
   --signer-workflow miracum/.github/.github/workflows/standard-build.yaml \
   --source-ref "refs/tags/${IMAGE_TAG}"

The images are built by a reusable workflow in miracum/.github, which is why --signer-workflow names that workflow rather than one in this repository.

The provenance is also pushed to the registry next to the image, so it can be enforced at deploy time - see GitHub's guide to enforcing artifact attestations with a Kubernetes admission controller.

Compose artifact verification

The getting-started Compose stack is an OCI artifact signed with cosign, with a build provenance attestation. Unlike the images, it is signed by this repository's own ci workflow. Verify it by digest, then run that digest:

ARTIFACT=ghcr.io/miracum/vfps/compose/getting-started:v1.22.4
DIGEST=$(crane digest "${ARTIFACT}")
ARTIFACT_DIGEST_PINNED="${ARTIFACT%:*}@${DIGEST}"
ARTIFACT_TAG="${ARTIFACT##*:}"

cosign verify \
   --certificate-oidc-issuer=https://token.actions.githubusercontent.com \
   --certificate-identity="https://github.com/miracum/vfps/.github/workflows/ci.yaml@refs/tags/${ARTIFACT_TAG}" \
   "${ARTIFACT_DIGEST_PINNED}"

gh attestation verify "oci://${ARTIFACT_DIGEST_PINNED}" --repo miracum/vfps

docker compose -f "oci://${ARTIFACT_DIGEST_PINNED}" up

Every image inside the artifact is pinned to a digest, so verifying the artifact fixes which images run. Verify the vfps image itself as shown above.