Skip to main content

7 docs tagged with "supply-chain"

View all tags

Cosign

Cosign is a container signing and verification tool used to secure container images and enforce supply chain integrity.

ImagePullSecrets Theft

Attack scenario demonstrating how attackers extract image pull secrets to gain unauthorized access to private container registries.

KBOM

KBOM (Kubernetes Bill of Materials) Toolkit generates comprehensive inventories of Kubernetes clusters, including components, images, and configurations.

Kubei

Kubei is a Kubernetes runtime vulnerability scanner that identifies vulnerabilities in container images across your cluster in real-time.

Supply Chain Attacks

How attackers compromise container images, dependencies, CI/CD pipelines, and Helm charts to infiltrate Kubernetes clusters.

Trivy

Overview, usage, and best practices for using Trivy to scan container images, file systems, and Kubernetes resources for vulnerabilities.

Trivy Operator

Trivy Operator provides Kubernetes-native security scanning by automatically scanning workloads for vulnerabilities, misconfigurations, secrets, and RBAC issues.