Sigstore Cosign Supply Chain Review

Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.

VincentChuWaiChow Updated

File contents

VincentChuWaiChow/vanguard-frontier-agentic/tree/main/skills/sigstore/sigstore-cosign-supply-chain-review commit a2b89193a8

Frequently asked questions

npx skillmds@latest add vincentchuwaichow/sigstore-cosign-supply-chain-review