Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign
Stars
12
Forks
5
Watchers
Open Issues
0
Overall repository health assessment
4.17.0
User
20
commits
Rename vulnerability report
16ff1a3
Add cosign public key
1cb8bed
Make clarifying changes to workflows
0a2565c
Rename build pipeline
0708893
Remove push trigger from nightly pipeline
1a4c8c8
Add nightly pipeline
36dd564
Use CI image in main workflow
e1c31e1
Create CI image
a184449
Add vulnerability scan attestation step
26a4866
Add SBOM attestation step
1c2efc9
Add step to scan for vulnerabilities
ffcce16
Add step to generate image SBOM
e82931e
Rename workflow file
ae7bed9
Break out image signing into separate job
991cbdf
Add image push and signing
53f7909