diff --git a/README.md b/README.md index 82cc25e16e..6aa22f6ace 100644 --- a/README.md +++ b/README.md @@ -77,6 +77,7 @@ If you're forking this repo you should [read the docs](https://docs.github.com/e - Call it `SIGNING_SECRET` and then paste the contents of `cosign.key` into the field and save it. Be careful to make sure it's the .key file and not the .pub file. It should look like this: ![image](https://user-images.githubusercontent.com/1264109/216735690-2d19271f-cee2-45ac-a039-23e6a4c16b34.png) - Copy the `cosign.pub` key into the root of your repository, replacing the key you got from here. + - Copy the instructions from the verification section of this readme and make adjustments to your container url. This part is important, users must have a method of verifying the image. The linux desktop must not lag behind in cloud when it comes to supply chain security, so we're starting right from the start! (Seriously don't skip this part) 1. Start making modifications to your Containerfile! - Change a few things and keep an eye on your Actions and Packages section of your repo, you'll generate a new image one every merge and additionally every day. - Follow the instructions at the top of this repo but this time with the `ghcr.io/yourusername/beagles` url and then you'll be good to go!