Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the registry came from your GitHub action.
-
Updated
Jan 31, 2023 - Dockerfile
Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the registry came from your GitHub action.
Minimal Alpine-based Docker image for kubectl with automatic updates, Cosign signing, and security scanning
Deterministic container hashes and container signing using Cosign, Kaniko and Google Cloud Build
Automated, secure Docker pipeline with image scanning and cloud/K8s deployment.
A Github Actions pipeline that builds safer containers
Docker image for Cosign using alpine linux as base image.
Add a description, image, and links to the cosign topic page so that developers can more easily learn about it.
To associate your repository with the cosign topic, visit your repo's landing page and select "manage topics."