Sachin Chaurasiya

Tag

#Sigstore

2 items tagged Sigstore.

All tags

Articles 2

DevSecOps intermediate

Attestations and Provenance: Binding the SBOM to the Image

Turn the SBOM from part 2 into a Cosign attestation bound to the image digest, verify it and read the predicate back, list what hangs off an image with cosign tree, and see what SLSA build provenance adds.

7 min read
DevSecOps intermediate

Sign and Verify Container Images with Cosign

Cosign with a key pair against a local registry: why the digest is the identity; signing and verifying; a moved tag failing verification while the digest passes; keyless signing as configuration; where the check goes.

9 min read