Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Allow setting build attestations

未關閉
#1,319 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
55/100
Issue 類型
功能
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
docker, typescript

研究方向

Start by locating where the CLI shells out to docker build/docker buildx build for image build and publish (search the src/spec-node tree for the build command construction), then decide where a new option for --attest/--provenance/--sbom flags should be threaded through CLI argument parsing into that call. Done means a user can pass the setting via the CLI and the resulting build command carries the attestation flags, verified by running a local build/publish. The issue does not specify the option name or surface, so confirm the interface with maintainers before coding.

由索引模型根據 Issue 內容生成。

描述

Docker buildx supports setting build attestations, including SBOM and provenance records. It would be nice to have some way to set this during image builds and publish.

主要語言
TypeScript
星號
3k
分支
462
平均合併
13 小時 28 分鐘
30 天內合併 PR
2

環境準備

在 Codespaces 中開啟

在瀏覽器裡用你自己的 GitHub 帳號啟動這個專案的開發容器。

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

devcontainers/cli 的其他 Issue

查看 devcontainers/cli 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。