wolfi-dev / community
Documents and tools powering the Wolfi OS community
☆17Updated 7 months ago
Related projects ⓘ
Alternatives and complementary repositories for community
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆56Updated this week
- ☆19Updated 3 months ago
- A CLI used to work with the Wolfi OSS project☆57Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- ☆35Updated 2 years ago
- A place for policy work group related proposals and prototypes.☆64Updated last month
- Scans SBOMs for vulnerabilities with Grype☆79Updated this week
- A Kubewarden Policy that detects usage of deprecated and dropped Kubernetes resources☆15Updated this week
- Helm Chart for deploying GUAC☆14Updated 3 months ago
- A pane of glass between you and your Kubernetes clusters.☆45Updated 10 months ago
- Interfaces and implementations for building Kubernetes releases.☆16Updated this week
- Sigstore user stories☆29Updated last year
- Go module to generate and transform VEX documents☆34Updated 2 weeks ago
- A sweet little formatter for YAML☆20Updated 2 weeks ago
- K8S Operator for Rekor☆20Updated last year
- Trivy plugin for OCI referrers☆20Updated 5 months ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆22Updated this week
- sigstore installation walkthrough, local☆56Updated 6 months ago
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆62Updated 3 years ago
- Security advisory data for Wolfi☆13Updated this week
- Helm charts for sigstore project☆65Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆30Updated 10 months ago
- Educational Resources for Software Supply Chain Security☆76Updated this week
- Comparison of Chainguard Images to others☆17Updated this week
- Go library for Sigstore signing and verification☆16Updated last year
- This is the documentation repo for the OpenCP project☆28Updated last year
- Software signing just got easier☆15Updated 11 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆70Updated this week