Verifying Build Provenance With Slsa Sigstore

Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.

mukul975 673da1f 5 files · 29.4 KB Updated 24.6k repo stars

File contents

mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/verifying-build-provenance-with-slsa-sigstore commit 673da1f3b0

Frequently asked questions

npx skillmds add mukul975/verifying-build-provenance-with-slsa-sigstore