From d456fd465bc2979ba99fbe82784dabb143485a01 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?V=C3=ADctor=20Cuadrado=20Juan?= <2196685+viccuad@users.noreply.github.com> Date: Fri, 18 Oct 2024 14:20:25 +0200 Subject: [PATCH] Update docs/tutorials/verifying-kubewarden.md MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: John Krug Signed-off-by: VĂ­ctor Cuadrado Juan <2196685+viccuad@users.noreply.github.com> --- docs/tutorials/verifying-kubewarden.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/tutorials/verifying-kubewarden.md b/docs/tutorials/verifying-kubewarden.md index a986e3509f..52d44870b3 100644 --- a/docs/tutorials/verifying-kubewarden.md +++ b/docs/tutorials/verifying-kubewarden.md @@ -75,7 +75,7 @@ ensure the secure supply chain of the images. You can find attestation files on the release page of the component or attached to the container image in the OCI registry. -We use Docker to build the images and their attestations. Therefore, the cosign +We use Docker to build the images and their attestations. However, the cosign command [does not yet support](https://github.com/sigstore/cosign/issues/2688) the verification of the attestations generated by Docker from the OCI registry. For this reason, you need to download the files from the release page or the