Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign
☆12Sep 15, 2021Updated 4 years ago
Alternatives and similar repositories for example-container-image-supply-chain-security
Users that are interested in example-container-image-supply-chain-security are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Integrates Spiffe and Vault to have secretless authentication☆99Jun 4, 2026Updated last week
- Submit SBOMs to GitHub's dependency submission API☆18Dec 4, 2025Updated 6 months ago
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- my goreleaser.yml files☆13May 7, 2026Updated last month
- Kubernetes tools in a "distroless" container☆13Oct 30, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆60Jun 3, 2026Updated last week
- Demo app duplicated in 5 languages (Go/JavaScript/Python/Ruby/Rust) showing how to go from source code to container image using melange+a…☆37Dec 24, 2023Updated 2 years ago
- SLSA level 3 action☆11Apr 26, 2024Updated 2 years ago
- an go event bus☆13May 16, 2023Updated 3 years ago
- Reports on the licenses used by a Go package and its dependencies.☆11Jul 24, 2024Updated last year
- OCI Working Group: Reference Types☆24Aug 25, 2022Updated 3 years ago
- Decode/encode CSV data into/from structs using reflection.☆15Dec 18, 2023Updated 2 years ago
- A CLI used to work with the Wolfi OSS project☆72Jun 8, 2026Updated last week
- To manage Docker Content Trust and Notary certificates☆13Jun 1, 2026Updated 2 weeks ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Comparison of Chainguard Images to others☆21Updated this week
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆19Jun 3, 2026Updated last week
- ☆18Apr 29, 2024Updated 2 years ago
- Various tools, images, etc. to support the Wolfi OSS project☆27Jun 8, 2026Updated last week
- Github Action implementation of SLSA Provenance Generation☆50Jun 8, 2026Updated last week
- This repository hosts the admission controller build on top of grype.☆20Jun 11, 2025Updated last year
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆14May 28, 2026Updated 2 weeks ago
- Resources to help vulnerability scanners☆14Updated this week
- Detect intrusions that happened in your Kubernetes cluster through audit logs using Falco☆63Jun 2, 2021Updated 5 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- 🔍 Rekor transparency log monitoring and alerting☆27Oct 2, 2023Updated 2 years ago
- ☆21Jun 1, 2026Updated 2 weeks ago
- Scans SBOMs for vulnerabilities with Grype☆87Jun 6, 2026Updated last week
- GitHub actions for the chainguard-images☆21Jun 8, 2026Updated last week
- Code repository for Practical XMPP, published by Packt☆10Jan 30, 2023Updated 3 years ago
- genAI agent providing security context, tooling for performing security analysis on CVE, components and more☆30Updated this week
- Security risk analysis for Kubernetes resources☆76Jan 23, 2025Updated last year
- Rode facilitates Automated Governance in your software supply chain. This repository contains the rode API which is the primary interface…☆51Jun 30, 2022Updated 3 years ago
- Template repository for testing CLI features of applications written in Go☆10Nov 14, 2021Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Tools for optical character recognition (OCR)☆10Jun 1, 2022Updated 4 years ago
- Context aware slog☆31Jun 8, 2026Updated last week
- Minimal container registry☆47Updated this week
- Dynamic GitHub Actions from Wolfi packages☆45May 5, 2026Updated last month
- Action to publish npm pacakges using One-Time Passwords☆13Jan 3, 2021Updated 5 years ago
- Gulp plugin for building durandaljs projects☆13Nov 10, 2019Updated 6 years ago
- sget is a keyless safe script retrieval and execution tool☆18Feb 7, 2022Updated 4 years ago