End-to-End Supply Chain Security for a Go Project: TUF on CI, cosign, and SLSA L3
3d ago · 12 min read · Adding cosign sign to a CI pipeline and calling it "signed releases" is a bit like putting a lock on a glass door. The lock works. The glass does not. Signing the image proves a specific digest was si
Join discussion

