Sigstore Cosign Supply Chain Review

Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.

aibot88 Updated 3 repo stars

File contents

aibot88/sec_skill_store/tree/main/skills/claudskills/sigstore-cosign-supply-chain-review commit 60a7324c38

Frequently asked questions

npx skillmds@latest add aibot88/sigstore-cosign-supply-chain-review