Images
13 imagesSecurity & supply chain images
Hardened container images in the security & supply chain category. Built from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest.
0 CVE
cert-manager-acmesolver
acmesolver component of cert-manager. The minimal HTTP server cert-manager runs as ephemeral pods to answer ACME http-01 challenge requests during certificate issuance.
image v1.21.1, 1.19.6, 1.20.3
Seguridad y cadena de suministrostandardApache-2.00 CVE
cert-manager-cainjector
cainjector component of cert-manager. Injects CA bundles into ValidatingWebhookConfigurations, MutatingWebhookConfigurations, APIServices, and conversion CRDs so the rest of the stack trusts cert-manager-issued certificates.
image v1.19.6, 1.21.1, 1.20.3
Seguridad y cadena de suministrostandardApache-2.00 CVE
cert-manager-controller
Core controller of cert-manager, the CNCF standard for X.509 certificate management on Kubernetes. Reconciles Certificate, Issuer, ClusterIssuer, and ACME order resources, automating issuance and renewal from Let's Encrypt, Vault, Venafi, and self-signed/CA issuers.
image v1.21.1, 1.19.6, 1.20.3
Seguridad y cadena de suministrostandardApache-2.00 CVE
cert-manager-webhook
Admission webhook component of cert-manager. Validates and mutates cert-manager API resources and serves the conversion webhook for its CRD versions.
image v1.19.6, 1.21.1, 1.20.3
Seguridad y cadena de suministrostandardApache-2.00 CVE
cosign
Sigstore's container-signing CLI. Keyless sign and verify of images, SBOMs, and attestations against the Fulcio/Rekor transparency log. Image only, no chart.
image v3.1.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
external-secrets
External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into Kubernetes Secrets. The single controller binary also serves the webhook and cert-controller, with every provider compiled in.
image v2.8.0
Seguridad y cadena de suministrostandardApache-2.00 CVE
grype
Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft. Image only, no chart.
image v0.116.1
Seguridad y cadena de suministrostandardApache-2.00 CVE
kyverno
Kubernetes-native policy engine for validating, mutating, and generating resources with no new language. Ships the controllers and CLI as static Go binaries on a hardened nonroot Wolfi base.
image v1.18.1
Seguridad y cadena de suministrostandardApache-2.00 CVE
opa
Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control, and configuration rules across the stack.
image v1.18.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
sealed-secrets
Sealed Secrets, the controller that lets you commit encrypted secrets to Git safely. A cluster-side private key decrypts SealedSecret resources into ordinary Kubernetes Secrets, so the encrypted form is the only thing that ever leaves the cluster.
image v0.36.6, 0.38.4, 0.37.0
Seguridad y cadena de suministrostandardApache-2.00 CVE
step-ca
Online private certificate authority and ACME server for issuing X.509 and SSH certificates. Single static Go binary on a hardened nonroot Wolfi base; config and data live under a writable volume.
image v0.30.2
Seguridad y cadena de suministrostandardApache-2.00 CVE
syft
Anchore's CLI for generating Software Bills of Materials (SBOMs) from container images and filesystems. Image only, no chart.
image v1.50.0
Seguridad y cadena de suministrostandardApache-2.0