In this video, we provide an in-depth exploration of Cosign, a tool developed by the Cloud Native Computing Foundation. Cosign allows for image signing which enhances supply chain transparency and enables organizations to verify the authentication and integrity of software images. Software Bill of Materials (SBOMS) can also be integrated with image cosigning, enabling traceability for improved risk management.
Chapters
0:00 Intro
0:45 Installation
1:18 Key pairing
1:50 Signing an image
2:55 Working with SBOMs
4:30 Final thoughts
4:42 Thanks for watching!
Resources
🎯 GitHub: https://github.com/sigstore/cosign
🎯 Learn More About SPDX: https://spdx.dev/
🎯 Learn More About CycloneDX: https://cyclonedx.org/
More Great SBOM Resources!
🌐 https://learnsbom.com
Contact Us!
📨 [email protected]
Music by Bensound
License code: FH38RQOCTBUIXQNZ
#sbom #attestation #security