Container signing, verification, and transparency log for OCI artifacts.
GoApache License 2.0active
4 projectsImage Lifecycle › Supply Chain
Container signing, verification, and transparency log for OCI artifacts.
GoApache License 2.0active
Framework for supply chain attestations; underpins SLSA and cosign provenance.
PythonOtheractive
Generate and verify in-toto attestations across the build pipeline.
GoApache License 2.0active
Kubernetes admission controller enforcing cosign signatures on container images.
GoOtheractive