kubernetes-sigs / tejolote
A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.
โ62Updated this week
Alternatives and similar repositories for tejolote
Users that are interested in tejolote are comparing it to the libraries listed below
Sorting:
- ๐ Rekor transparency log monitoring and alertingโ27Updated last year
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.โ64Updated last week
- โ20Updated 9 months ago
- sigstore the hard way!โ111Updated last year
- Helm charts for sigstore projectโ74Updated this week
- sigstore installation walkthrough, localโ58Updated last year
- Transparenty Immutable Container Image Tagsโ20Updated last year
- โ56Updated 2 years ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for soโฆโ91Updated last week
- A CLI used to work with the Wolfi OSS projectโ60Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.โ43Updated last year
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable suppโฆโ131Updated this week
- Integrates Spiffe and Vault to have secretless authenticationโ88Updated last week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworksโ31Updated 3 weeks ago
- Sigstore user storiesโ30Updated last year
- Keyless Git signing with cosign!โ11Updated 3 years ago
- Dynamic GitHub Actions from Wolfi packagesโ43Updated last year
- Anchore Kubernetes Inventory can poll Kubernetes Cluster API(s) to tell Anchore Enterprise which Containers and Images are currently in-uโฆโ65Updated this week
- Container Storage Interface components for SPIFFEโ61Updated last week
- ๐ฎ โ๏ธ to integrate OPA Gatekeeper's new ExternalData feature with cosign to determine whether the images are valid by verifying their sigโฆโ78Updated last year
- kubectl plugin for signing Kubernetes manifest YAML files with sigstoreโ81Updated last week
- โ35Updated 3 years ago
- Mattermost builderโ11Updated 3 years ago
- Trivy plugin for OCI referrersโ23Updated last year
- This tool allows using a SPIFFE JWT to authenticate to AWS APIsโ34Updated 11 months ago
- This projects contains pre-made policies for Kubernetes Validating Admission Policies. This policy library is based on Kubescape controlsโฆโ55Updated last week
- Enabling Software Supply Chain Security Capabilities in ArgoCDโ86Updated 2 years ago
- vexctl is a tool to attest VEX impact statementsโ44Updated 2 years ago
- A Kubernetes CSI plugin to automatically mount SPIFFE certificates to Pods using ephemeral volumesโ79Updated this week
- native go library for installation and management of apk packagesโ29Updated 11 months ago