The ImageValidatingPolicy keyless example states that regular expressions are supported through identities.subjectRegExp / issuerRegExp, but the sample immediately below uses a wildcard in the exact subject field (https://github.com/myorg/myrepo/.github/workflows/*).\n\nKyverno exposes a dedicated subjectRegExp option in the API/verifier path, so the sample would be clearer and less ambiguous if it used an anchored subjectRegExp for the GitHub Actions workflow identity while keeping the exact OIDC issuer.\n\nI can submit a small docs-only PR with that correction and build verification.
The
ImageValidatingPolicykeyless example states that regular expressions are supported throughidentities.subjectRegExp/issuerRegExp, but the sample immediately below uses a wildcard in the exactsubjectfield (https://github.com/myorg/myrepo/.github/workflows/*).\n\nKyverno exposes a dedicatedsubjectRegExpoption in the API/verifier path, so the sample would be clearer and less ambiguous if it used an anchoredsubjectRegExpfor the GitHub Actions workflow identity while keeping the exact OIDC issuer.\n\nI can submit a small docs-only PR with that correction and build verification.