chainguard-dev / cosign-ecs-verify
Lambda function for verifying signed images in ECS
☆33Updated last year
Alternatives and similar repositories for cosign-ecs-verify
Users that are interested in cosign-ecs-verify are comparing it to the libraries listed below
Sorting:
- This tool allows using a SPIFFE JWT to authenticate to AWS APIs☆34Updated 11 months ago
- Dynamic GitHub Actions from Wolfi packages☆43Updated last year
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆49Updated last year
- CLI for searching Rego policies☆105Updated 3 years ago
- Integrates Spiffe and Vault to have secretless authentication☆88Updated 2 weeks ago
- sigstore installation walkthrough, local☆58Updated last year
- Unified Policy Engine☆57Updated this week
- 🎟 Voucher creates attestations for Binary Authorization☆73Updated last month
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆92Updated this week
- Pre-commit git hooks for Open Policy Agent (OPA) and Rego development☆66Updated 3 years ago
- A simple tool for converting Rego (OPA) rule into command.☆28Updated 2 years ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated last month
- 🔍 Rekor transparency log monitoring and alerting☆27Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆62Updated this week
- ☆56Updated 2 years ago
- An SBOM query language and associated utilities☆54Updated last year
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- ☆42Updated 6 months ago
- ☆31Updated last month
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Updated last year
- TerraDagger is a Go package for managing your infrastructure-as-code through containers.☆34Updated 11 months ago
- A collection of Dagger modules powered by Dagger.☆13Updated 5 months ago
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆64Updated last week
- Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign☆11Updated 3 years ago
- ☆29Updated 9 months ago
- AWS CloudFormation template sync controller for Flux☆54Updated 9 months ago
- Falco Running with Ptrace(2) for Kernel Events☆36Updated 4 years ago
- Transparenty Immutable Container Image Tags☆20Updated last year