Verifying Build Provenance With Slsa Sigstore

Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.

thedixitjain 86dad80 5 files · 29.7 KB Updated 2 repo stars

File contents

thedixitjain/the-mega-skill-library/tree/main/library/security-and-compliance/verifying-build-provenance-with-slsa-sigstore commit 86dad80e13

Frequently asked questions

npx skillmds add thedixitjain/verifying-build-provenance-with-slsa-sigstore