Container image signing and supply chain security

17 repos

Container image signing, verification, and provenance tracking systems built primarily in Go. This cluster centers on the Sigstore ecosystem—including cosign (image signing tool), rekor (transparency log), fulcio (certificate authority), and related infrastructure—along with container registry tooling and Bazel-based build automation. Developers exploring this area will find tools for cryptographically securing container artifacts, managing signing keys and certificates, and auditing the full supply chain from build through deployment.

Go · 8
Makefile · 2
HCL · 1
Python · 1
Shell · 1
Java · 1
security ·2,035
supply-chain ·2,035
wolfi ·1,979
transparency-log ·1,256
provenance ·1,256
sigstore ·779
cosign ·746
chainguard ·693
oci-image ·693
audit ·693