Projects with this topic
Sort by:
-
A curated kaniko for GitLab Runner. Signed and attested container builds: six image variants per release, built in UBI9 and shipped from scratch, standard and FIPS 140-3, with CycloneDX SBOM, SLSA provenance and OpenVEX.
Updated -
The conformance contract for projects under gitlab-com/public-sector.
Updated -
Harness Software Supply Chain CI/CD components for GitLab. SBOM, SLSA, Artifact Signing, and Policy Enforcement
UpdatedUpdated -
Chapter 5: a container image at cutover phase. The unsigned-image gap is planted, and the red pipeline is the point: watch the floor block it.
Updated