Context
Release jobs create provenance, SBOM attestations, and keyless cosign signatures, but post-publish validation currently confirms only that the image manifest exists.
Scope
Make supply-chain verification an explicit post-publish gate for all Docker Hub images.
Acceptance criteria
Context
Release jobs create provenance, SBOM attestations, and keyless cosign signatures, but post-publish validation currently confirms only that the image manifest exists.
Scope
Make supply-chain verification an explicit post-publish gate for all Docker Hub images.
Acceptance criteria