Projects with this topic
-
CI/CD catalog components for regulated container builds. Standardizes buildah, cosign signing, verification, and release across public-sector projects. Consumed via GitLab CI component includes.
Updated -
A curated kaniko for GitLab Runner. Seven signed image variants per release on UBI9, including a FIPS-strict path for GODEBUG=fips140=only environments.
Updated -
Deployment shim for storyping. Downloads signed binary from storyping project, verifies cosign signature, extracts assets, and deploys to GitLab Pages. Not a standalone tool.
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
CI/CD Catalog components for FROM-scratch bootc images
Updated -
A quick demo project highlighting how once can sign a container image to later verify it when rolling it out in production
Updated -
-
This project contains shell scripts I use to create keys and certificates in order to explore and evaluate using cosign to attach certificates and certificate chains to OCI images.
Updated -
Reusable single pipeline configuration unit for cosign sign and verify operations
Updated