Login
Download
Skill UI
Browse and discover
15558+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
attestations
, found
3
results
Default
Newest
Most Downloaded
Enforcing Secure Container Deployment with GCP
implementing-gcp-binary-authorization
mukul975/Anthropic-Cybersecurity-Skills
163
Binary Authorization is a critical Google Cloud security control that enforces policy-based deployment rules. It mandates that only container images with valid cryptographic attestations (proof of successful vulnerability scanning, code reviews, etc.) can be deployed to GKE or Cloud Run. Use this guide to establish robust supply chain security and compliance controls for your cloud-native applications.
View Details
Verifying Container Image Provenance with Cosign
implementing-image-provenance-verification-with-cosign
mukul975/Anthropic-Cybersecurity-Skills
343
This guide details implementing robust container image provenance verification using Cosign, a Sigstore tool. It covers key-based and keyless (OIDC) signing methods, enabling secure supply chain practices. Users can sign images, attach critical attestations (such as SBOMs and vulnerability scans), and enforce verification in CI/CD pipelines and Kubernetes environments to ensure high integrity and trust.
View Details
Supply Chain Integrity With In-Toto
implementing-supply-chain-security-with-in-toto
mukul975/Anthropic-Cybersecurity-Skills
472
In-toto is a CNCF standard project used to verify the integrity of software supply chains. It generates cryptographically signed attestations (link metadata) at every stage of the CI/CD pipeline, proving exactly what artifacts were produced and who authorized the process. This is crucial for securing container builds and ensuring compliance against tampering.
View Details
1
Language
简体中文
English