devguy :verified: · @developerguy
366 followers · 584 posts · Server hachyderm.io

📯 As one of the fans of the both @GoReleaser and projects, I'm super excited to see that support has been finally landed on ! 🥳
😏 Yep, you heard that right! That means you can build your @OCI_ORG images with while still using !
✍️ You can even sign the images you built with using support!
🌟 I'm writing a blog post about that but you can use the following documentation to start learning more about that integration between two ↙️
goreleaser.com/customization/k

#ko #goreleaser #Cosign

Last updated 1 year ago

Caleb Woodbine ✅ · @calebwoodbine
80 followers · 494 posts · Server mastodon.nz
devguy :verified: · @developerguy
365 followers · 564 posts · Server hachyderm.io

💊Every treatment starts with accepting the diagnosis! Embrace the truth☝️
"You can be the next victim of the Software Supply Chain Attacks" UNLESS...
✍️Sign your software ()
🔔Do vulnerability scanning ( )
🚨 Protection at runtime ( )

#Cosign #trivy #grype #kyverno #policycontroller

Last updated 1 year ago

devguy :verified: · @developerguy
365 followers · 563 posts · Server hachyderm.io

I've corrected the signing part in @github Actions starter workflows for @Docker Publish workflow to be able to prevent risks of script injection by using intermediate environment variables, details🧵

1⃣ Here is the PR for you if you want to take a look at the details about the improvement:
github.com/actions/starter-wor

2⃣ Also you can have a look at the @github's official documentation to understand the problem better: docs.github.com/en/actions/sec

#Cosign

Last updated 1 year ago

devguy :verified: · @developerguy
355 followers · 536 posts · Server hachyderm.io

I'm super glad to see that two of the great projects and now signed by another awesome project by @sigstore ✍️ and made 💃 provenance available, thanks to @JamesLaverack and Luca Guerra! 🚀
1️⃣github.com/jetstack/paranoia/p
2️⃣github.com/falcosecurity/falco

#falcoctl #paranoia #Cosign #SLSA

Last updated 1 year ago

devguy :verified: · @developerguy
353 followers · 525 posts · Server hachyderm.io

🚀The long-awaited task of @gitlab OIDC support has been rolled out to staging. You can visit the page for the flag values if you're using , thanks Hayden Blauzvern for bringing it to our attention! 🥳
@cpanato already created an example🎖️
gitlab.com/cpanato/testing-cos

#Cosign

Last updated 1 year ago

devguy :verified: · @developerguy
336 followers · 452 posts · Server hachyderm.io

☝️🛎️I'm glad to announce that the project by @aquasecteam is signed by by @sigstore to guarantee that it has not been tampered with by having strong integrity ⛓️🆔
github.com/aquasecurity/tracee

#tracee #Cosign

Last updated 1 year ago

devguy :verified: · @developerguy
332 followers · 427 posts · Server hachyderm.io

1⃣ One of the first packages that I got involved with is . I'm one of the contributors to the project for a while and learned so much stuff from
@comedordexis
. Now, I'm one of the maintainers of that project in !
➡️ nix-env -iA nixpkgs.cosign

#Cosign #nixos

Last updated 1 year ago

devguy :verified: · @developerguy
326 followers · 400 posts · Server hachyderm.io

This is a really great blog post by the Virtru Platform Engineering team which they talked about the strategies to secure their software supply chain by using open-source tools @sigstore
@kyverno🥇

virtru.com/blog/securing-kuber

#Cosign #sigstore #projectsigstore #kyverno #softwaresupplychainsecurity #supplychainsecurity

Last updated 1 year ago

devguy :verified: · @developerguy
326 followers · 401 posts · Server hachyderm.io

🎊I'm super glad to announce that @sigstore v2.0.0 was released officially!

☝️There were lots of🌱amazing features, 🐛bug fixes, and✨improvements included in that release!

🥇Another important milestone was achieved for the team.

blog.sigstore.dev/cosign-2-0-r

#Cosign #sigstore

Last updated 1 year ago

devguy :verified: · @developerguy
320 followers · 383 posts · Server hachyderm.io

📢You can reach out to our talk at KCD Pakistan with @furkanturkal about creating a secure base image with using @wolfi packages and using it with to build OCI-compliant container images and signing them in keyless and verifying them with
➡️ youtube.com/watch?v=W1Xct6ZtmH

#apko #ko #Cosign #kyverno

Last updated 1 year ago

nachshon_r · @nachshon_r
85 followers · 490 posts · Server kolektiva.social

@Alexander_R ! I mean, the US has A TON of , so, wtf if Ukraine uses a few aryan nutbags of their own as target practise for Russian soldiers (who need the practise)? They've just been looking for something to fight for—for glory. I can't imagine white nationalists fighting for a democracy headed by a prominently jewish Jew, and doing it all for the end purpose of fulfilling Hitler's ambitions. Sorry...no. Not buying it.

#Cosign #nazis #ukraine

Last updated 2 years ago

devguy :verified: · @developerguy
317 followers · 365 posts · Server hachyderm.io

@beltranrubo so glad to hear that; what about signing these with as a next step, I can do that for you :blobfoxdealwithitfingerguns:

#Cosign

Last updated 2 years ago

Dennis Irsigler · @dirsigler
148 followers · 332 posts · Server infosec.exchange

Explain to me like I am 5, because I literally don’t understand what is doing and why.
Which problem is it solving ?

#sigstore #Cosign #cncf #cloudsecurity

Last updated 2 years ago

devguy :verified: · @developerguy
314 followers · 357 posts · Server hachyderm.io

🌟Great repository template by @mchmarny about the showcase of building an @oci_org image with , signing with using , generating provenance using slsa-github-generator and verifications with policy-controller by @sigstore🔥 ➡️ github.com/mchmarny/s3cme/

#ko #Cosign #kms #SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
301 followers · 338 posts · Server hachyderm.io

f you missed the event organized by @chainguard_dev yesterday about , , , and , don't worry; you can still watch it on demand from the Crowdcast platform 👇 Thx to @strongjz for a fantastic talk 👏
crowdcast.io/c/software-signin

#Gitsign #Cosign #tektoncd #chains

Last updated 2 years ago

devguy :verified: · @developerguy
291 followers · 304 posts · Server hachyderm.io

Wow 🤩 from now on v1.26, the @kubernetesio is starting to sign release artifacts too, in addition to the container images, of course using the @sigstore tool 🙈 don’t forget to read this blog post to learn more about the process 👇
kubernetes.io/blog/2022/12/12/

#Cosign

Last updated 2 years ago

puerco · @puerco
355 followers · 96 posts · Server hachyderm.io

RT @saschagrunert@twitter.com

Kubernetes v1.26.0-rc.1 released yesterday! 🥳

Do you know that you can already verify all binary artifacts using :

tlog entry verified with uuid: 5d54b39222e3fa9a21bcb0badd8aac939b4b0d1d9085b37f1f10b18a8cd24657 index: 8173886
Verified OK

gist.github.com/saschagrunert/

🐦🔗: twitter.com/saschagrunert/stat

#Cosign

Last updated 2 years ago

Sascha · @sascha
141 followers · 5 posts · Server m6n.io

Kubernetes v1.26.0-rc.1 released yesterday! 🥳

Do you know that you can already verify all binary artifacts using :

tlog entry verified with uuid: 5d54b39222e3fa9a21bcb0badd8aac939b4b0d1d9085b37f1f10b18a8cd24657 index: 8173886
Verified OK

gist.github.com/saschagrunert/

#Cosign

Last updated 2 years ago

devguy :verified: · @developerguy
271 followers · 274 posts · Server hachyderm.io

@anderseknert I think @sigstore can be part of this signing flow. The sign-blob command can be used while signing the bundle?

#Cosign

Last updated 2 years ago