Summary
Replace all REPLACE_WITH_VERIFIED_DIGEST placeholders in the SourceOS smoke-runner image lane with verified known-good digests.
This follows the merged release-lane scaffolds:
Scope
Resolve and pin digests for:
images/sourceos-smoke-runner/image-policy.yaml base image
images/sourceos-smoke-runner/task-image-policy.yaml task images
- Tekton pipeline defaults where release-grade enforcement requires digest-pinned refs
Task images to verify:
- Buildah image
- Syft image
- Grype image
- Cosign image
- Skopeo image(s)
- BusyBox/utility image
Acceptance criteria
Non-goals
- Do not change SourceOS catalog publication authority in this issue
- Do not enable release promotion automatically
- Do not introduce proprietary tooling
Progress impact
Completing this moves the OS build substrate v0 from ~99% to effectively complete for digest policy enforcement.
Summary
Replace all
REPLACE_WITH_VERIFIED_DIGESTplaceholders in the SourceOS smoke-runner image lane with verified known-good digests.This follows the merged release-lane scaffolds:
Scope
Resolve and pin digests for:
images/sourceos-smoke-runner/image-policy.yamlbase imageimages/sourceos-smoke-runner/task-image-policy.yamltask imagesTask images to verify:
Acceptance criteria
REPLACE_WITH_VERIFIED_DIGESTinimage-policy.yamlREPLACE_WITH_VERIFIED_DIGESTintask-image-policy.yamlNon-goals
Progress impact
Completing this moves the OS build substrate v0 from ~99% to effectively complete for digest policy enforcement.