Topic: sigstore Goto Github
Some thing interesting about sigstore
Some thing interesting about sigstore
sigstore,Project that demonstrates the implementation of SLSA L3 with Github Workflows and Sigstore. Bonus: binary authorization with Kyverno.
Organization: albasystems
sigstore,Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect
Organization: appvia
sigstore,Enabling Software Supply Chain Security Capabilities in ArgoCD
Organization: argoproj-labs
sigstore,Transparenty Immutable Container Image Tags
Organization: chainguard-dev
Home Page: https://tlogistry.dev
sigstore,Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the registry came from your GitHub action.
User: chrisns
sigstore,Cosign CircleCI orb. To learn more about cosign visit the GitHub repo
User: cpanato
Home Page: https://github.com/sigstore/cosign
sigstore,Does GitHub support gitsign signatures yet?
User: cpanato
sigstore,A Rekor crawler and monitor
User: flxw
Home Page: https://rekor-monitor.flxw.de
sigstore,[Archived] Blog about kyverno verify images which uses cosign from sigstore under the hood
User: garethahealy
Home Page: https://cloud.redhat.com/blog/software-supply-chain-security-on-openshift-with-kyverno-and-cosign
sigstore,Google Container Analysis data import utility, supports OSS vulnerability scanner reports, SLSA provenance and sigstore attestations.
Organization: googlecloudplatform
sigstore,Example goreleaser + github actions config with keyless signing and SBOM generation
Organization: goreleaser
Home Page: https://goreleaser.com
sigstore,Demo to showcase how to build a golang application using ko. Sign and push the image to the container registry using https://sigstore.dev. Apply policy controller on Kubernetes to allow only signed images.
User: kameshsampath
sigstore,Sign your artifacts, source code or container images using Sigstore tools, Save the Signatures you want to use, and Validate & Control the deployments to allow only the known Sources based on Signatures, Maintainers & other payloads automatically.
Organization: kube-tarian
Home Page: https://sigrun.dev
sigstore,A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Organization: kubernetes-sigs
sigstore,Kubernetes admission webhook that uses cosign tools Container Sign Verify
Organization: kubeservice-stack
sigstore,Stream, Mutate and Sign Images with AWS Lambda and ECR
User: martinbaillie
Home Page: https://martin.baillie.id/wrote/stream-mutate-and-sign-images-with-aws-lambda-and-ecr/
sigstore,Demo repository for the PyConFR 2023 talk "Introduction to Sigstore: cryptographic signatures made easier"
User: mayacostantini
sigstore,A guide for setting up Sigstore with Keycloak as an identity provider
User: mayacostantini
sigstore,Ansible roles to deploy Sigstore components
User: mayacostantini
sigstore,🔍 Rekor transparency log monitoring and alerting
User: nsmith5
sigstore,Verify Sigstore Gitsign commit signatures
User: operatorequals
sigstore,Software signing just got easier
User: rewanthtammana
Home Page: https://rewanthtammana.com/sigstore-the-easy-way/
sigstore,This GitHub Action use kaniko and Amazon Linux container with nitro-cli to build a reproducible AWS Nitro Enclaves EIF file and its information.
User: richardfan1126
sigstore,Supply Chain Security does not need to be difficult
User: shibumi
sigstore,🔮 ✈️ to integrate OPA Gatekeeper's new ExternalData feature with cosign to determine whether the images are valid by verifying their signatures
Organization: sigstore
sigstore,Pulumi GitHub Sync for sigstore
Organization: sigstore
Home Page: https://sigstore.dev
sigstore,Plugin for Helm to integrate the sigstore ecosystem
Organization: sigstore
sigstore,Supply chain security for ML
Organization: sigstore
sigstore,Common go library shared across sigstore services and clients
Organization: sigstore
Home Page: https://sigstore.dev
sigstore,Conformance testing for Sigstore clients
Organization: sigstore
Home Page: https://sigstore.dev
sigstore,Tools & services used to help in the development flow of sigstore
Organization: sigstore
Home Page: https://sigstore.dev
sigstore,An experimental Rust crate for sigstore
Organization: sigstore
Home Page: https://sigstore.github.io/sigstore-rs/sigstore/
sigstore,An Ansible collection for using Sigstore to verify file signatures
Organization: smallstep
Home Page: https://smallstep.com
sigstore,Gitsign plugin for asdf version manager
User: spencergilbert
Home Page: https://github.com/asdf-vm/asdf
sigstore,An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
Organization: sse-secure-systems
Home Page: https://sse-secure-systems.github.io/connaisseur/
sigstore,sigstore the hard way!
Organization: stacklok
Home Page: https://stacklok.github.io/sigstore-the-hard-way/
sigstore,Example code repo for blog post https://chainguard.dev/posts/2022-01-07-cosign-aws-codepipeline
User: strongjz
sigstore,Samples showing how to secure the supply chain for Java applications.
User: thomasvitale
sigstore,Sample CI/CD pipeline for creating container images with provenance details.
User: toddysm
sigstore,Rust clients for the Fulcio and Rekor APIs
Organization: trailofbits
Home Page: https://docs.rs/sigstore-apis/latest/sigstore_apis/index.html
sigstore,Example of GitHub Actions, goreleaser and cosign to release a Go based CLI program.
User: wolfeidau
Home Page: https://github.com/wolfeidau/gh-cosign-goreleaser
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.