A hands-on walkthrough of container image security using Cosign for signing and Trivy for vulnerability scanning. Covers local image signing with Cosign, keyless signing via GitHub Actions OIDC tokens, configuring Trivy to fail CI builds on CRITICAL/HIGH vulnerabilities, blocking unsafe Docker pushes, and generating SBOMs. Also touches on how Kyverno/OPA Gatekeeper can enforce policies to block unsigned or unsafe images from entering Kubernetes clusters.

3m read timeFrom infosecwriteups.com
Post cover image
Table of contents
Cosign: Proving an image is really yoursTrivy: Stopping vulnerabilities before they move forward

Sort: