#

cosign

https://static.github-zh.com/github_avatars/sigstore?size=40

Common go library shared across sigstore services and clients

Go 490
5 小时前
https://static.github-zh.com/github_avatars/sse-secure-systems?size=40
Go 456
20 小时前
https://static.github-zh.com/github_avatars/ChristofferNissen?size=40

Import Helm Charts to OCI registries, optionally with vulnerability patching

Go 378
2 天前
https://static.github-zh.com/github_avatars/sigstore?size=40
157
3 天前
https://static.github-zh.com/github_avatars/stacklok?size=40
117
1 个月前
https://static.github-zh.com/github_avatars/philips-labs?size=40
Go 92
10 小时前
https://static.github-zh.com/github_avatars/intelops?size=40

Compage - Low-Code Framework to develop Rest API, gRPC, dRPC, GraphQL, WebAssembly, microservices, FaaS, Temporal workloads, IoT and edge services, K8s controllers, K8s CRDs, K8s custom APIs, K8s Oper...

Go 85
1 年前
https://static.github-zh.com/github_avatars/sigstore?size=40

🔮 ✈️ to integrate OPA Gatekeeper's new ExternalData feature with cosign to determine whether the images are valid by verifying their signatures

Go 78
1 年前
https://static.github-zh.com/github_avatars/developer-guy?size=40

This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)

Go 63
4 年前
https://static.github-zh.com/github_avatars/goreleaser?size=40

Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations

Go 58
15 小时前
https://static.github-zh.com/github_avatars/appvia?size=40

Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect

JavaScript 23
2 天前
https://static.github-zh.com/github_avatars/martinbaillie?size=40

Stream, Mutate and Sign Images with AWS Lambda and ECR

Go 20
4 年前
https://static.github-zh.com/github_avatars/Dentrax?size=40
TypeScript 17
4 年前
https://static.github-zh.com/github_avatars/chrisns?size=40

Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the registry came from your GitHub action.

Dockerfile 14
3 年前
https://static.github-zh.com/github_avatars/onedr0p?size=40

My personal stop-gap mirror of OCI Helm Charts.

YAML 13
6 个月前
https://static.github-zh.com/github_avatars/kube-tarian?size=40

Sign your artifacts, source code or container images using Sigstore tools, Save the Signatures you want to use, and Validate & Control the deployments to allow only the known Sources based on Signatur...

Go 12
2 年前
https://static.github-zh.com/github_avatars/GoogleCloudPlatform?size=40

Google Container Analysis data import utility, supports OSS vulnerability scanner reports, SLSA provenance and sigstore attestations.

Go 12
5 天前
https://static.github-zh.com/github_avatars/ekristen?size=40
Go 11
12 天前
loading...
Website
Wikipedia