Changelog
All notable changes to the container-supply-chain skill.
2.0.1 - 2026-08-02
Added
- Build context hygiene —
.dockerignoreplacement and depth traps (references/distribution-artifact-leakage.md, Docker and OCI Image Checks). Two production-verified pitfalls from.apm/known-pitfalls.md: (1).dockerignoremust live at the build context root, not the service subdirectory — a monorepo context above the service dir tars up.venv//.git//caches and fails witharchive/tar: write too longon ACR remote builds; (2) use**/target(nottarget) to exclude nested build-artifact dirs (src-tauri/target/,node_modules,dist,.next) that a root-only entry misses.
[Unreleased] - 2026-07-18
AzureFeeds newsletter sweep — incident scenario citations from Microsoft Security blogs.
Added
- AsyncAPI npm supply chain compromise — incident scenario (Microsoft Security blog, July 15, 2026). Real-world attack chain: GitHub Actions pwn request → import-time payload delivery via the AsyncAPI npm package. Use as a scenario citation for npm/OCI provenance verification, build-time integrity checks, and GH Actions pwn-request hardening. Pairs with
dependabot-configurationskill. Source: https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/. - ACR Stealer intrusion chains — incident scenario (Microsoft Security blog, July 16, 2026). Two observed attack chains: (1) WebDAV-based ClickFix with Python loaders and blockchain C2; (2) MSHTA-initiated PowerShell chain with steganographic payload delivery. Relevant to container-image runtime threat modelling and image-isolation decisions. Source: https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/.
2.0.0 - 2026-05-28
Phase 2 deep factual freshness audit applied. SLSA, in-toto, Notation, Cosign, and registry-side trust surfaces re-verified against current upstream specs (2026-05-28).
Changed
- SLSA v1.1 baseline. Reference the SLSA v1.1 specification (published 2024-08) rather than v1.0. The build-track levels (L1-L4) and source-track concepts unchanged at the conceptual level, but the provenance v1 schema field set and the producer-conformance language were tightened.
- in-toto attestation framework v1.0: predicate types versioned independently of the framework. SBOM predicate (
https://spdx.dev/Document/https://cyclonedx.org/bom), provenance predicate (https://slsa.dev/provenance/v1), and vulnerability-scan predicate (https://in-toto.io/attestation/vulns/v0.2) are the current canonical IDs. - Notation v1 GA.
notationCLI v1.x is the canonical OCI-native signing path for production; the v0.x line is retired. Sign withnotation sign --signature-format coseand verify with a trust policy that pins both the certificate identity and the signature algorithm. - Cosign keyless via Sigstore remains the preferred path for OSS / public workflows; private workloads should use Notation v1 with an enterprise CA or Cosign with a customer-managed Fulcio.
provenance:disabled on multi-arch builds is now treated as a legitimate default rather than a "documented exception" for ACR / Artifact Registry due to upstream BuildKit + registry interop bugs (moby/buildkit#5078). Re-enable per-arch provenance once the registry confirms manifest-list provenance support.
Added
- Trust-policy worked example for Notation v1 with
trustedIdentitiespinned to the publishing org's certificate subject andsignatureVerification.levelset tostrict. - Registry-side enforcement reference: Sigstore policy-controller and Kyverno verifyImages as the in-cluster trust gate;
gh attestation verifyon the CI runner is defense-in-depth, not the primary gate. - GUAC ingestion pattern for centralised attestation graph: SBOMs, SLSA provenance, and Notation/Cosign signatures flow into a single queryable graph for incident response and compliance evidence.
Verification
- SLSA specification v1.1 - https://slsa.dev/spec/v1.1 (verified 2026-05-28).
- in-toto attestation framework v1.0 spec (verified 2026-05-28).
- Notation v1.x release notes and trust-policy reference (verified 2026-05-28).
- Sigstore Cosign release notes and keyless flow documentation (verified 2026-05-28).
- BuildKit issue tracker for multi-arch provenance (moby/buildkit#5078, verified 2026-05-28).
1.0.0 - Initial release
- Initial skill covering SBOM generation, SLSA provenance, Notation/Cosign signing, attestation verification on the CI runner, and registry-side policy enforcement.