Images
41 imagesSecurity & supply chain images
Hardened container images in the security & supply chain category. Built from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest.
0 CVE
dependency-track-frontend
The OWASP Dependency-Track web UI, the official release bundle served by a nonroot, read-only-rootfs nginx with a conf.d hook for proxying /api to…
image v5.1.2
الأمن وسلسلة التوريدstandardApache-2.00 CVE
dive
dive, the explorer for container image layers: shows each layer's files and the space wasted across them, and gates image efficiency in CI with --ci.…
image v0.13.1
الأمن وسلسلة التوريدstandardMIT0 CVE
external-secrets
External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into…
image v2.11.0, 2.12.0
الأمن وسلسلة التوريدstandardApache-2.00 CVE
fulcio
Fulcio, the Sigstore certificate authority: it issues short-lived code-signing certificates bound to OIDC identities, for keyless signing with…
image v1.7.1, 1.8.8
الأمن وسلسلة التوريدstandardApache-2.00 CVE
gitleaks
Gitleaks, the secret scanner for git history, directories and stdin. Built from source (static Go) with the git client included for history scans.…
image v8.30.1
الأمن وسلسلة التوريدstandardMIT0 CVE
grype
Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft. Image only, no chart.
image v0.120.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
ko
ko, the builder that turns Go applications into container images with no Dockerfile. Built from the release tag as one static binary, shipped with…
image v0.19.1, 0.18.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
kyverno
Kubernetes-native policy engine for validating, mutating, and generating resources with no new language. Ships the controllers and CLI as static Go…
image v1.19.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
notation
Notation, the Notary Project CLI to sign and verify container images and OCI artifacts against trust policies. Built from source (static Go). Image…
image v1.3.2
الأمن وسلسلة التوريدstandardApache-2.00 CVE
opa
Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control,…
image v1.21.1
الأمن وسلسلة التوريدstandardApache-2.00 CVE
opa-gatekeeper
OPA Gatekeeper, the Kubernetes admission controller for Rego policies (ConstraintTemplates and Constraints, validating and mutating webhooks, audit…
image v3.23.1, 3.21.1, 3.22.2
الأمن وسلسلة التوريدstandardApache-2.00 CVE
openscap
OpenSCAP, the SCAP compliance scanner (oscap for XCCDF and OVAL evaluation, datastream validation and reports), with the scap-security-guide content,…
image v1.4.4
الأمن وسلسلة التوريدstandardLGPL-2.1+