Cosign Verification Policies in Production
Writing cosign verification policies that actually pass production deployment gates requires more precision than the examples suggest. Here is what we have learned.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Writing cosign verification policies that actually pass production deployment gates requires more precision than the examples suggest. Here is what we have learned.
Cosign makes signing and verifying container images straightforward. Here's everything you need to know to implement it in your pipeline.
Sigstore's general availability in October 2022 made cryptographic signing accessible to every developer. Here's why this is a watershed moment.
Container image signing has gone through multiple iterations. Here is where the OCI standards stand now and what you need to implement.
Weekly insights on software supply chain security, delivered to your inbox.