When using the docker exporter and requesting that an SBOM be attached, the build completes successfully and generates the SBOM but it is not exported anywhere.
Reproduction
$ docker buildx build -t ccrone/test:sbom --push --sbom=true .
[+] Building 14.6s (12/12) FINISHED docker:desktop-linux
...
=> [linux/arm64] generating sbom using docker.io/docker/buildkit-syft-scanner:stable-1 0.2s
=> exporting to image 0.0s
=> => exporting layers 0.0s
=> => writing image sha256:4f064f99cb7967224178fbd83e118c4c21730c23e33b3290e3d77f9114124104 0.0s
=> => naming to docker.io/ccrone/test:sbom 0.0s
=> pushing ccrone/test:sbom with docker 7.0s
=> => pushing layer 5a743ec78593 4.0s
=> => pushing layer b2191e2be29d
Only the image manifest is present:
$ docker buildx imagetools inspect ccrone/test:sbom
Name: docker.io/ccrone/test:sbom
MediaType: application/vnd.docker.distribution.manifest.v2+json
Digest: sha256:ca3f1f2d995a286d60582e037243143e9183e1071a03351a2180bf694812d85c
Expectation
I would expect that we add a warning that this exporter doesn't support attestations or that we error out.
We might also want to update the docs to make it more clear that this is only supported by the container driver or if the containerd image store is enabled in Engine.
When using the docker exporter and requesting that an SBOM be attached, the build completes successfully and generates the SBOM but it is not exported anywhere.
Reproduction
Only the image manifest is present:
Expectation
I would expect that we add a warning that this exporter doesn't support attestations or that we error out.
We might also want to update the docs to make it more clear that this is only supported by the container driver or if the containerd image store is enabled in Engine.