Signing Artifacts - Choose Your Own Adventure: The Treacherous Trek to Security
In this episode, we'll figure out which tool for signing artifacts we should adopt. The contestants are Notary Project, Sigstore, and Open Policy Containers.
Vote for your choice of a tool for signing artifacts at https://cloud-native.slack.com/archiv...
This and all other episodes are available at • You Choose .
More information about the "Choose Your Own Adventure" project including the source code and links to all the videos can be found at https://github.com/vfarcic/cncf-demo.
٩( ᐛ )و Whitney's YouTube Channel → / @wiggitywhitney
#Notary #Sigstore #OPC
▬▬▬▬▬▬ 🔗 Additional Info 🔗 ▬▬▬▬▬▬
🔗 mTLS and Network Policies: https://github.com/vfarcic/cncf-demo/...
🎬 Ensuring Software Authenticity: Introduction to Notary Project: • ⚡️ Enlightning - Ensuring Software Au...
🎬 Signed, Sealed, Delivered, I’m Yours! An Introduction to Sigstore: • ⚡️ Enlightning - Signed, Sealed, Deli...
🎬 Signing and Verifying Container Images With Sigstore Cosign and Kyverno: • Signing and Verifying Container Image...