sigstore / cosignLinks
Code signing and transparency for containers and binaries
☆5,418Updated last week
Alternatives and similar repositories for cosign
Users that are interested in cosign are comparing it to the libraries listed below
Sorting:
- Go library and CLIs for working with container registries☆3,599Updated this week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆7,975Updated this week
- Write tests against structured configuration data using the Open Policy Agent Rego query language☆3,071Updated last week
- Supply-chain Levels for Software Artifacts☆1,754Updated last week
- Cloud Native Runtime Security☆8,395Updated last week
- 🐊 Policy Controller for Kubernetes☆4,061Updated this week
- CLI for building apps using Cloud Native Buildpacks☆2,835Updated last week
- Build OCI images from APK packages directly without Dockerfile☆1,463Updated this week
- A vulnerability scanner for container images and filesystems☆11,030Updated this week
- OCI registry client - managing content like artifacts, images, packages☆2,005Updated this week
- Hubble - Network, Service & Security Observability for Kubernetes using eBPF☆3,988Updated last week
- 🧵 CLI tool for directly patching container images!☆1,480Updated this week
- eBPF-based Security Observability and Runtime Enforcement☆4,267Updated this week
- The SPIFFE Runtime Environment☆2,120Updated this week
- KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adh…☆3,321Updated this week
- Boundary enables identity-based access management for dynamic infrastructure.☆3,965Updated this week
- External Secrets Operator reads information from a third-party service like AWS Secrets Manager and automatically injects the values as K…☆6,133Updated this week
- Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastruct…☆2,514Updated this week
- Cloud native secrets management for developers - never leave your command line for secrets.☆3,151Updated last year
- Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in …☆2,992Updated last week
- 🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.☆4,057Updated this week
- Notary is a project that allows anyone to have trust over arbitrary collections of data☆3,285Updated last year
- Validation of best practices in your Kubernetes clusters☆3,325Updated this week
- Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.☆5,194Updated 3 months ago
- Software Supply Chain Transparency Log☆1,027Updated last week
- Tfsec is now part of Trivy☆6,925Updated last week
- Work with remote images registries - retrieving information, images, signing content☆10,019Updated last week
- Cost monitoring for Kubernetes workloads and cloud costs☆6,171Updated this week
- Instant Kubernetes-Native Application Observability☆6,239Updated last week
- Superseded by https://github.com/aquasecurity/trivy-operator☆1,368Updated last week