Skip to content
#

cosign

Here are 28 public repositories matching this topic...

🚀 DevSecOps intro elective — 10 hands-on labs + 2 bonus hardening OWASP Juice Shop: threat modeling (STRIDE/Threagile), signed commits & secret scanning, SBOM/SCA, SAST + DAST, IaC security (Checkov/KICS), container & supply-chain hardening (Trivy, Cosign), runtime detection with Falco, and DefectDojo vuln management.

  • Updated Jun 12, 2026
  • Shell

A hands-on lab toolkit for container security, from CIS-benchmark fundamentals to architectural trust governance. 12 production-grade labs covering image hardening, signing, supply chain attestation, admission control, and runtime debugging. Built from real Fortune 500 cluster experience.

  • Updated May 29, 2026
  • Shell

End-to-end secure software supply chain reference implementation: hadolint + gitleaks lint, Trivy CVE scan + SARIF, CycloneDX SBOM, Cosign keyless signing + SBOM attestation, gated before GHCR push, runtime enforcement via Kyverno admission control. Self-proving on every push.

  • Updated May 13, 2026
  • Shell

Improve this page

Add a description, image, and links to the cosign topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the cosign topic, visit your repo's landing page and select "manage topics."

Learn more