cosign topic
zarf
DevSecOps for Air Gap & Limited-Connection Systems. https://zarf.dev/
connaisseur
An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
sigstore
Common go library shared across sigstore services and clients
container-image-sign-and-verify-with-cosign-and-opa
This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)
cosigneth
Container Image Signing & Verifying on Ethereum [Testnet]
ocistow
Stream, Mutate and Sign Images with AWS Lambda and ECR
goreleaser-example-supply-chain
Example goreleaser + github actions config with keyless signing and SBOM generation
spiffe-vault
Integrates Spiffe and Vault to have secretless authentication
cosign-keyless-admission-webhook
Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect