Images
41 imagesSecurity & supply chain images
Hardened container images in the security & supply chain category. Built from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest.
0 CVE
dependency-track-frontend
The OWASP Dependency-Track web UI, the official release bundle served by a nonroot, read-only-rootfs nginx with a conf.d hook for proxying /api to…
image v5.1.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
dive
dive, the explorer for container image layers: shows each layer's files and the space wasted across them, and gates image efficiency in CI with --ci.…
image v0.13.1
Seguridad y cadena de suministrostandardMIT0 CVE
external-secrets
External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into…
image v2.11.0, 2.12.0
Seguridad y cadena de suministrostandardApache-2.00 CVE
fulcio
Fulcio, the Sigstore certificate authority: it issues short-lived code-signing certificates bound to OIDC identities, for keyless signing with…
image v1.7.1, 1.8.8
Seguridad y cadena de suministrostandardApache-2.00 CVE
gitleaks
Gitleaks, the secret scanner for git history, directories and stdin. Built from source (static Go) with the git client included for history scans.…
image v8.30.1
Seguridad y cadena de suministrostandardMIT0 CVE
grype
Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft. Image only, no chart.
image v0.120.1
Seguridad y cadena de suministrostandardApache-2.00 CVE
ko
ko, the builder that turns Go applications into container images with no Dockerfile. Built from the release tag as one static binary, shipped with…
image v0.19.1, 0.18.1
Seguridad y cadena de suministrostandardApache-2.00 CVE
kyverno
Kubernetes-native policy engine for validating, mutating, and generating resources with no new language. Ships the controllers and CLI as static Go…
image v1.19.1
Seguridad y cadena de suministrostandardApache-2.00 CVE
notation
Notation, the Notary Project CLI to sign and verify container images and OCI artifacts against trust policies. Built from source (static Go). Image…
image v1.3.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
opa
Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control,…
image v1.21.1
Seguridad y cadena de suministrostandardApache-2.00 CVE
opa-gatekeeper
OPA Gatekeeper, the Kubernetes admission controller for Rego policies (ConstraintTemplates and Constraints, validating and mutating webhooks, audit…
image v3.23.1, 3.21.1, 3.22.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
openscap
OpenSCAP, the SCAP compliance scanner (oscap for XCCDF and OVAL evaluation, datastream validation and reports), with the scap-security-guide content,…
image v1.4.4
Seguridad y cadena de suministrostandardLGPL-2.1+