Skip to content

dhi: update attestations - #25666

Open
craig-osterhout wants to merge 2 commits into
docker:mainfrom
craig-osterhout:dhi-attestations-update
Open

dhi: update attestations#25666
craig-osterhout wants to merge 2 commits into
docker:mainfrom
craig-osterhout:dhi-attestations-update

Conversation

@craig-osterhout

Copy link
Copy Markdown
Contributor

Description

  • Added changelog attestation.
  • Updated the wording to be less authoritative, noting that the actual attestations for a given image may differ and directing users to Docker Scout or the Docker Hub UI for the full list.

Related issues or tickets

https://docker.slack.com/archives/C04300R4G5U/p1785235912818699

Reviews

  • Editorial review

Signed-off-by: Craig Osterhout <[email protected]>
@craig-osterhout
craig-osterhout requested a review from a team July 28, 2026 15:22
@craig-osterhout craig-osterhout added status/review Pull requests that are ready for review area/dhi labels Jul 28, 2026
@netlify

netlify Bot commented Jul 28, 2026

Copy link
Copy Markdown

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 4ca318a
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6a68d04e6947390008ef4505
😎 Deploy Preview https://deploy-preview-25666--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

This is a small, well-scoped update that adds a DHI changelog attestation row, notes that the actual attestation set may vary per image, and surfaces both Docker Scout and the Docker Hub UI as ways to inspect attestations. No high or medium issues were found.

Three minor (low) observations (not blocking):

  1. Line 65 — Redundant caveat: "The actual set for a given image may differ." is slightly redundant with the preceding "may be included". Consider merging: "The following table lists attestations that may be included with a DHI; the actual set varies by image variant."

  2. Line ~117 — Same pattern in Helm charts section: "The actual set for a given chart may differ." has the same redundancy.

  3. Line 92 — Capitalisation inconsistency: The new row uses "DHI changelog" (lowercase c) while the sibling row uses "DHI Image Sources" (title case I, S). Align casing: either "DHI Changelog" or adjust "DHI Image Sources" to "DHI image sources".

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟡 NEEDS ATTENTION

Comment thread content/manuals/dhi/explore/security-concepts/attestations.md Outdated
Signed-off-by: Craig Osterhout <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dhi status/review Pull requests that are ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants