Skip to content

fix: remove retired Docker Content Trust check - #314

Open
Eljees wants to merge 1 commit into
goodwithtech:masterfrom
Eljees:agent/remove-retired-content-trust-check
Open

Eljees wants to merge 1 commit into
goodwithtech:masterfrom
Eljees:agent/remove-retired-content-trust-check

Conversation

@Eljees

@Eljees Eljees commented Jul 19, 2026

Copy link
Copy Markdown

Summary

  • stop emitting CIS-DI-0005 and unregister the Docker Content Trust assessor
  • remove the retired checkpoint metadata from scanner expectations and output examples
  • mark trusted base-image verification as unsupported instead of recommending DOCKER_CONTENT_TRUST=1

Docker is retiring DCT/Notary v1, and Docker Official Image pulls can fail when DOCKER_CONTENT_TRUST=1 is set. The current INFO finding therefore recommends a setting that is no longer generally safe.

Reference: https://www.docker.com/blog/retiring-docker-content-trust/

Testing

  • CGO_ENABLED=0 go test ./pkg/... (Go 1.26.3 container)

Fixes #289

@Eljees
Eljees marked this pull request as ready for review July 26, 2026 20:35
@Eljees

Eljees commented Jul 28, 2026

Copy link
Copy Markdown
Author

Ping - is dropping the retired Docker Content Trust check still wanted here? Happy to adjust, or to close if it's not.

@Eljees
Eljees force-pushed the agent/remove-retired-content-trust-check branch from 92d891d to 710a48e Compare July 29, 2026 18:56
@Eljees

Eljees commented Aug 9, 2026

Copy link
Copy Markdown
Author

Ping on this one and #318, #319, #320 - the oldest has been open since 19 July. They are independent of each other and can be taken in any order.

@Eljees

Eljees commented Aug 29, 2026

Copy link
Copy Markdown
Author

Ping on this one, #318, #319 and #320 — no maintainer review yet on any of the four. #314 has been open since 19 July, the other three since 27 July. All four remain independent, conflict-free, single-package fixes with their own test, and can be reviewed/merged in any order. Happy to rebase or adjust any of them if priorities have changed.

@Eljees Eljees closed this Sep 21, 2026
@Eljees Eljees reopened this Sep 21, 2026
@Eljees

Eljees commented Sep 21, 2026

Copy link
Copy Markdown
Author

A note on why this and #318, #319, #320 just closed and reopened — that was me, deliberately, and nothing about the branches changed.

All four showed an empty checks section. The cause is not that CI is unconfigured: the three workflows did start on 29 July and each finished as failure with zero jobs, which is what an expired "approve workflows" request looks like through the API. GitHub drops the pending approval about thirty days after the run is raised, and with no jobs there are no check runs, so the pull request page shows nothing where CI should be while the Actions tab shows a red cross.

Closing and reopening resets that request. All four now have three fresh runs sitting at action_required instead — an honest "waiting for approval" rather than a red cross that looks like failing tests. Whenever you next have a moment, the approve button on any of them will run the suite.

Heads are unchanged: #314 710a48e2, #318 715d6f0c, #319 af97950a, #320 cacd6e2d.

For context on what they are, smallest first: #319 falls back after an image transport init failure, #318 avoids sudo-argument false positives, #320 honours the standard Docker host environment variables, and this one removes the retired Docker Content Trust check. They are independent of each other, so any can go in alone.

Signed-off-by: Eljees <3.14hell@gmail.com>
@Eljees
Eljees force-pushed the agent/remove-retired-content-trust-check branch from 710a48e to 70871f5 Compare September 21, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

deprecation of CIS-DI-0005

1 participant