Skip to content

Commit d13ef90

Browse files
AlexKantor87claude
andcommitted
docs: drop dir suggestion from artifact-type=docker note
Source-dir fingerprinting only works as an end-to-end identity if the runtime side also fingerprints the source dir. Standard Kosli runtime reporters fingerprint the running image, so suggesting dir as a generic swap is misleading — the attested and running artifacts would never link. Push and oci are the safe answers for the typical case. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 797eabc commit d13ef90

1 file changed

Lines changed: 1 addition & 2 deletions

File tree

‎cmd/kosli/root.go‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -52,8 +52,7 @@ Note: ^--artifact-type=docker^ reads the image's repo digest via the local Docke
5252
The image must have been pushed to or pulled from a registry for a repo digest to exist;
5353
a freshly built image (just ^docker build^) will not have one. If the image is already in
5454
a registry, prefer ^--artifact-type=oci^, which fetches the digest directly from the
55-
registry without needing a local Docker daemon. To fingerprint the source instead, use
56-
^--artifact-type=dir^ on the build context.
55+
registry without needing a local Docker daemon.
5756
5857
`
5958

0 commit comments

Comments
 (0)