Example of GitHub Actions, goreleaser and cosign to release a Go based CLI program.
-
Updated
Jun 16, 2024 - Go
Example of GitHub Actions, goreleaser and cosign to release a Go based CLI program.
(landing area for upstream contributions and carried patches)
Kubernetes admission webhook that uses cosign tools Container Sign Verify
Demo to showcase how to build a golang application using ko. Sign and push the image to the container registry using https://sigstore.dev. Apply policy controller on Kubernetes to allow only signed images.
Tools & services used to help in the development flow of sigstore
Sign your artifacts, source code or container images using Sigstore tools, Save the Signatures you want to use, and Validate & Control the deployments to allow only the known Sources based on Signatures, Maintainers & other payloads automatically.
Stream, Mutate and Sign Images with AWS Lambda and ECR
Transparenty Immutable Container Image Tags
🔍 Rekor transparency log monitoring and alerting
Example goreleaser + github actions config with keyless signing and SBOM generation
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
Enabling Software Supply Chain Security Capabilities in ArgoCD
Add a description, image, and links to the sigstore topic page so that developers can more easily learn about it.
To associate your repository with the sigstore topic, visit your repo's landing page and select "manage topics."