Skip to content

document signed GitHub Actions cache reuse#199

Open
crazy-max wants to merge 1 commit into
docker:mainfrom
crazy-max:readme-signed-cache
Open

document signed GitHub Actions cache reuse#199
crazy-max wants to merge 1 commit into
docker:mainfrom
crazy-max:readme-signed-cache

Conversation

@crazy-max
Copy link
Copy Markdown
Member

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@crazy-max crazy-max requested review from dvdksn and tonistiigi May 13, 2026 12:12
@crazy-max crazy-max requested a review from a team as a code owner May 13, 2026 12:12
Comment thread README.md
unexpected flags, or producing misleading provenance.

* **Signed cache reuse.**
GitHub Actions cache storage is repository-scoped but writable by actors who
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could use some editing for better clarity. It is not really obvious that when you say "writable by actors" then this doesn't apply to this workflow.

Better to start with something like. "All cache produced by this action is signed and verified before importing. This is because ..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants