Sigstore
2 tutorials in this category.
01
How to Verify Package Provenance with SLSA Attestations
Understand provenance statuses, create policies that require verified provenance, and interpret provenance data in the BOM.
11
How to Author, Sign, and Load Signed Policy Bundles
Ship custom Rego rules as a cosign-signed bundle that the server verifies at load — author, sign, verify-at-load, promote — with the same signed bundle enforced at PR, install, K8s admission, and runtime, and the bundle digest stamped on each policy decision and carried into the audit trail.