Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign
☆12Sep 15, 2021Updated 4 years ago
Alternatives and similar repositories for example-container-image-supply-chain-security
Users that are interested in example-container-image-supply-chain-security are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- native go library for installation and management of apk packages☆31Jun 5, 2024Updated 2 years ago
- Threat Modeling Tool Extension for Penetration Tester (TMTe4PT)☆12Mar 2, 2022Updated 4 years ago
- Integrates Spiffe and Vault to have secretless authentication☆101Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- Amazon Web Services (AWS) Microsoft Threat Modeling Tool Template☆16Aug 19, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Github Action that uses the cloudsmith cli to interact with the Cloudsmith API (pushes, etc)☆16Oct 23, 2025Updated 9 months ago
- GitHub action to generate a CycloneDX SBOM for Python☆14Apr 23, 2026Updated 3 months ago
- Submit SBOMs to GitHub's dependency submission API☆19Dec 4, 2025Updated 7 months ago
- my goreleaser.yml files☆13Jul 16, 2026Updated last week
- nginx image demo☆19Sep 11, 2023Updated 2 years ago
- Kubernetes tools in a "distroless" container☆13Oct 30, 2023Updated 2 years ago
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆60Jul 1, 2026Updated 3 weeks ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated this week
- Demo app duplicated in 5 languages (Go/JavaScript/Python/Ruby/Rust) showing how to go from source code to container image using melange+a…☆37Dec 24, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SLSA level 3 action☆12Apr 26, 2024Updated 2 years ago
- ☆24Updated this week
- an go event bus☆13May 16, 2023Updated 3 years ago
- OCI Working Group: Reference Types☆24Aug 25, 2022Updated 3 years ago
- Reports on the licenses used by a Go package and its dependencies.☆11Jul 24, 2024Updated 2 years ago
- Go tool to declaratively bump dependencies.☆13Jul 9, 2026Updated 2 weeks ago
- Decode/encode CSV data into/from structs using reflection.☆15Dec 18, 2023Updated 2 years ago
- A CLI used to work with the Wolfi OSS project☆72Updated this week
- To manage Docker Content Trust and Notary certificates☆13Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Comparison of Chainguard Images to others☆21Updated this week
- Python module that generates token to authenticate against a Kubernetes EKS Cluster☆12Jul 8, 2018Updated 8 years ago
- Stream, Mutate and Sign Images with AWS Lambda and ECR☆20Oct 28, 2021Updated 4 years ago
- Various tools, images, etc. to support the Wolfi OSS project☆27Updated this week
- sigstore the hard way!☆120May 29, 2026Updated last month
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆19Updated this week
- ☆18Apr 29, 2024Updated 2 years ago
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- Sigstore A2A Agent Signing☆23Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆53Mar 4, 2026Updated 4 months ago
- This repository hosts the admission controller build on top of grype.☆20Jun 11, 2025Updated last year
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆14Updated this week
- A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492☆13Mar 12, 2022Updated 4 years ago
- Resources to help vulnerability scanners☆14Updated this week
- Kubernetes operator to work with the aws-auth configmap☆13Oct 11, 2023Updated 2 years ago
- 🔍 Rekor transparency log monitoring and alerting☆27Oct 2, 2023Updated 2 years ago