Skip to content

docs: document kit signing and verification - #25791

Merged
dvdksn merged 1 commit into
docker:mainfrom
dvdksn:codex/document-kit-signing
Aug 20, 2026
Merged

docs: document kit signing and verification#25791
dvdksn merged 1 commit into
docker:mainfrom
dvdksn:codex/document-kit-signing

Conversation

@dvdksn

@dvdksn dvdksn commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Summary

Document Sigstore signing and verification for kits, including keyless and key-based workflows, OCI sign-on-push, trusted signer enforcement, and the signed-content boundary. This covers the functionality introduced by docker/sandboxes#4446.

@netlify /ai/sandboxes/customize/kits/

Deploy preview

Generated by Codex

@dvdksn dvdksn added this to the sbx/v0.39.0 milestone Aug 11, 2026
@dvdksn
dvdksn requested review from a team and cdupuis August 11, 2026 14:54
@dvdksn
dvdksn marked this pull request as ready for review August 11, 2026 14:54

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

The new Sign and verify kits section is clear, well-structured, and follows the Docker documentation style guide. No style violations, AI-isms, or content accuracy issues were found in the added lines.

The section covers:

  • Keyless and key-based signing/verification flows with correct command syntax
  • OCI referrer storage and the combined push-and-sign workflow
  • ZIP kit limitation (no verifiable signatures)
  • Trusted signer policy setup with both keyless and key-based examples
  • Accurate description of the signed-content boundary and its mutable-dependency caveat

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟡 NEEDS ATTENTION

Comment thread content/manuals/ai/sandboxes/customize/kits.md Outdated
Comment thread content/manuals/ai/sandboxes/customize/kits.md Outdated

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

The new "Sign and verify kits" section is well-structured and covers keyless signing, key-based signing, OCI referrer storage, and signature enforcement policy. No high or medium issues found. Three minor low-severity observations are noted as inline comments.

Comment thread content/manuals/ai/sandboxes/customize/kits.md Outdated
Comment thread content/manuals/ai/sandboxes/customize/kits.md Outdated
Comment thread content/manuals/ai/sandboxes/customize/kits.md Outdated

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

The new Sign and verify kits section is well-structured, technically clear, and free of AI-isms, marketing language, and broken Markdown. No high or medium severity issues were found.

A few minor observations (below the threshold for inline comments):

  • Line ~476: The relative clause content that install and startup commands download is slightly hard to parse. Consider content fetched by install and startup commands.
  • Line ~452: OIDC appears in CLI flags but OpenID Connect is never introduced with the abbreviation in prose. A first-use expansion (e.g., OpenID Connect (OIDC) issuer) would help readers connect the concept to the flag.

The kits guide did not cover the Sigstore signing support added in docker/sandboxes#4446. Document keyless and key-based workflows, OCI sign-on-push, signature enforcement, and the signed-content boundary.

Co-Authored-By: Claude <noreply@anthropic.com>
@dvdksn
dvdksn force-pushed the codex/document-kit-signing branch from a5a8a7a to 72b51b8 Compare August 19, 2026 11:01
@netlify

netlify Bot commented Aug 19, 2026

Copy link
Copy Markdown

Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 72b51b8
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6a858d210f3f8a0008cd5d9b
😎 Deploy Preview https://deploy-preview-25791--docsdocker.netlify.app/ai/sandboxes/customize/kits/
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dvdksn
dvdksn merged commit bf486b2 into docker:main Aug 20, 2026
19 checks passed
@dvdksn
dvdksn deleted the codex/document-kit-signing branch August 20, 2026 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants