An open API service indexing awesome lists of open source software.

https://github.com/thomasvitale/scs-demo-oci


https://github.com/thomasvitale/scs-demo-oci

Last synced: 6 months ago
JSON representation

Awesome Lists containing this project

README

          

# Supply Chain Security Demo - OCI

Sample to showcase how to configure GitHub Actions to perform the following:

* sign an OCI artifact with Sigstore Cosign
* verify the signature on an OCI artifact
* generate, sign and publish a SLSA provenance attestation
* generate, sign and publish a SBOM.