openpubkey / verify-docker-cli-plugin
A docker CLI plugin for verifying signed attestations on images
☆13Updated last year
Alternatives and similar repositories for verify-docker-cli-plugin:
Users that are interested in verify-docker-cli-plugin are comparing it to the libraries listed below
- Sigstore user stories☆29Updated last year
- native go library for installation and management of apk packages☆29Updated 7 months ago
- OCI viewer☆16Updated 7 months ago
- A library for representing OCI image layers in an abstract filesystem☆27Updated 4 years ago
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Updated last year
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl …☆10Updated this week
- Create a dedicated IaaS instance per Pod to mitigate container breakout (including CPU vulnerabilities depending on the instance type)☆22Updated 5 years ago
- Simple example for using an in-cluster BuildKit instance for container builds☆19Updated 5 years ago
- Transparenty Immutable Container Image Tags☆20Updated last year
- Integrates Spiffe and Vault to have secretless authentication☆85Updated this week
- Terraform provider to perform OCI image operations☆13Updated last week
- Pluggable generator for creating, using and sharing reusable templates that can be applied directly, generated into operator, helm chart …☆11Updated 3 years ago
- Kubernetes security scanner based on the open-source container vulnerability scanner Trivy.☆23Updated 4 years ago
- Tool to automate build instructions generation☆30Updated this week
- AWS Signer Plugin for Notation☆12Updated this week
- etcd-k8s-extract takes in an etcd data directory or db file used in kubernetes, extracts the kubernetes resources and then writes the res…☆34Updated 3 weeks ago
- A Kubewarden Policy that detects usage of deprecated and dropped Kubernetes resources☆15Updated this week
- This tool allows using a SPIFFE JWT to authenticate to AWS APIs☆34Updated 7 months ago
- ☆12Updated 4 years ago
- Tool to interact with Docker registry objects.☆24Updated 3 months ago
- Kubernetes tools in a "distroless" container☆13Updated last year
- An query language and interactive tooling to work with SBOM data.☆14Updated 3 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- ☆20Updated 6 months ago
- A CLI used to work with the Wolfi OSS project☆59Updated this week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆60Updated this week
- A simple (experimental) tool for generating Kubernetes manifest from templates based on CUE☆24Updated 2 years ago
- Ergonomic OCI registry Go API☆16Updated last year
- ☆21Updated last year
- Go module to generate and transform VEX documents☆37Updated last week