autonomy oci pull-policy¶
Retrieve the policy bundle attached to an OCI image
Usage¶
autonomy oci pull-policy [flags]
Options¶
--image string OCI image reference (required)
--out string output path for the pulled policy bundle (default "policy.tar")
Options inherited from parent commands¶
--require-signed-manifest Refuse to start if the SHA256SUMS release manifest or its cosign signature is missing/invalid (Tier 2 binary-integrity check; default: build-time compile-in via -ldflags -X, build-hardened artifacts=true, all others=false)
See also¶
autonomy oci— Manage OCI artifact attachments (lock, policy bundle)