Skip to content

Commit

Permalink
Add a sentence about cosign and supply chain security
Browse files Browse the repository at this point in the history
Signed-off-by: Jirka Kremser <[email protected]>
  • Loading branch information
jkremser committed Oct 31, 2023
1 parent 2a7e91a commit 79caa96
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions self-assessment.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,7 @@ Quick reference information, later used for indexing.
| Security insights | https://github.com/k8gb-io/k8gb/blob/master/SECURITY-INSIGHTS.yml |
| Cosign pub-key | https://github.com/k8gb-io/k8gb/blob/master/cosign.pub |

### Intended Use

To increase the software supply chain security, we encourage our users to consume k8gb container images with Kyverno's admission webhook that will ensure that
images are signed and nobody had tempered with them. Our public key that can be used to verify this is in the root or our repository.

0 comments on commit 79caa96

Please sign in to comment.