Sign, attest, and enforce: a supply chain security pipeline that blocks unsigned images at Kubernetes admission time
-
Updated
Jul 31, 2026 - Python
Sign, attest, and enforce: a supply chain security pipeline that blocks unsigned images at Kubernetes admission time
Automated DevSecOps pipeline using GitHub Actions, Docker, and Trivy vulnerability scanning for container security validation.
Add a description, image, and links to the container-security-automation-devops topic page so that developers can more easily learn about it.
To associate your repository with the container-security-automation-devops topic, visit your repo's landing page and select "manage topics."