Techtide Sigstore Cosign Supply Chain Review

Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.

TechTideOhio Updated

File contents

TechTideOhio/techtide-harness-kit/tree/main/skills/sigstore/techtide-sigstore-cosign-supply-chain-review commit 7900846d06

Frequently asked questions

npx skillmds@latest add techtideohio/techtide-sigstore-cosign-supply-chain-review