Repository navigation

#

cosign

Common go library shared across sigstore services and clients

Go
488
1 天前

An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster

Go
456
1 天前

Import Helm Charts to OCI registries, optionally with vulnerability patching

Go
362
1 个月前

Cosign Github Action

153
3 天前

sigstore the hard way!

115
14 天前

Integrates Spiffe and Vault to have secretless authentication

Go
90
21 小时前

Compage - Low-Code Framework to develop Rest API, gRPC, dRPC, GraphQL, WebAssembly, microservices, FaaS, Temporal workloads, IoT and edge services, K8s controllers, K8s CRDs, K8s custom APIs, K8s Operators, K8s hooks, etc. with minimal coding and by automatically applying best practice methods like software supply chain security measures, SBOM, openAPI, cloudevents, etc. Auto generate code after defining requirements in UI as diagram.

Go
84
1 年前

🔮 ✈️ to integrate OPA Gatekeeper's new ExternalData feature with cosign to determine whether the images are valid by verifying their signatures

Go
78
1 年前

This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)

Go
62
4 年前

Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations

Go
58
5 天前

Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect

JavaScript
23
1 个月前

Stream, Mutate and Sign Images with AWS Lambda and ECR

Go
20
4 年前

Container Image Signing & Verifying on Ethereum [Testnet]

TypeScript
17
3 年前

Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the registry came from your GitHub action.

Dockerfile
14
3 年前

My personal stop-gap mirror of OCI Helm Charts.

YAML
13
5 个月前

Sign your artifacts, source code or container images using Sigstore tools, Save the Signatures you want to use, and Validate & Control the deployments to allow only the known Sources based on Signatures, Maintainers & other payloads automatically.

Go
13
2 年前

Google Container Analysis data import utility, supports OSS vulnerability scanner reports, SLSA provenance and sigstore attestations.

Go
12
4 小时前
Go
11
6 天前