Project Hummingbird, Red Hat's catalog of hardened minimal container images, supports reproducible builds that allow users to verify images are bit-for-bit identical to published blobs. Using SLSA provenance attestations and SBOMs generated by the Konflux build system, anyone can rebuild a Hummingbird image with just cosign and

6m read timeFrom developers.redhat.com
Post cover image
Table of contents
Hummingbird reproducibilityHow it worksReaching reproducibilityLooking ahead

Sort: