Supply Chain Security Slsa Sigstore

Software supply chain security: keyless Sigstore/cosign signing with OIDC, SLSA build levels, in-toto provenance attestations, SBOM attestation, and signature plus identity verification enforced at Kubernetes admission with Kyverno or the sigstore policy-controller. Use when release artifacts or container images need signing, provenance or attestation, when a customer or auditor asks which SLSA level a build meets, or when only trusted and verified images should be allowed to run in a cluster.

mchittineni Updated

File contents

mchittineni/cloud-platform-skills/tree/main/.agents/skills/supply-chain-security-slsa-sigstore commit e5b81fe07e

Frequently asked questions

npx skillmds@latest add mchittineni/supply-chain-security-slsa-sigstore