Images
41 imagesSecurity & supply chain images
Hardened container images in the security & supply chain category. Built from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest.
0 CVE
oras
ORAS, the CLI that pushes and pulls arbitrary artifacts (SBOMs, signatures, Helm charts, any file) to and from OCI registries. Built from source…
image v1.3.4
Security & supply chainstandardApache-2.00 CVE
podman
Podman, the daemonless container engine with a Docker-compatible CLI, built from source and run rootless as uid 1001 with crun, conmon, netavark and…
image v6.0.2, 6.1.3
Security & supply chainstandardApache-2.00 CVE
polaris
Fairwinds Polaris, the Kubernetes configuration validator. Audits running workloads or YAML files against best-practice checks (security contexts,…
image v10.1.8, 10.0.0, 10.2.5
Security & supply chainstandardApache-2.00 CVE
policy-reporter
Policy Reporter, Kyverno's PolicyReport aggregator. Watches PolicyReport results from Kyverno and other engines, serves them over a REST API and…
image v3.10.0, 3.9.0, 3.11.0
Security & supply chainstandardMIT0 CVE
rekor-tiles
Rekor v2, the Sigstore transparency log, rebuilt on Trillian Tessera tiles: it needs no Trillian or MySQL. Built from source with the POSIX storage…
image v2.3.0, 2.1.0, 2.2.1
Security & supply chainstandardApache-2.00 CVE
sealed-secrets
Sealed Secrets, the controller that lets you commit encrypted secrets to Git safely. A cluster-side private key decrypts SealedSecret resources into…
image v0.38.4, 0.40.0, 0.39.1
Security & supply chainstandardApache-2.00 CVE
skopeo
Skopeo, the daemonless CLI to inspect, copy, sync and delete container images between registries and storage transports. Built from source (static…
image v1.24.1
Security & supply chainstandardApache-2.00 CVE
step-ca
Online private certificate authority and ACME server for issuing X.509 and SSH certificates. Single static Go binary on a hardened nonroot Wolfi…
image v0.30.2
Security & supply chainstandardApache-2.00 CVE
step-issuer
step-issuer, smallstep's cert-manager external issuer. StepIssuer and StepClusterIssuer resources sign cert-manager CertificateRequests through a…
image v0.12.0, 0.11.0, 0.10.2
Security & supply chainstandardApache-2.00 CVE
syft
Anchore's CLI for generating Software Bills of Materials (SBOMs) from container images and filesystems. Image only, no chart.
image v1.54.1
Security & supply chainstandardApache-2.00 CVE
tetragon
Tetragon eBPF runtime-security agent and the tetra CLI, built from source. Watches process execution, file access and network activity in the kernel,…
image v1.7.1
Security & supply chainstandardApache-2.00 CVE
tetragon-operator
Tetragon's operator, which installs and maintains the TracingPolicy and PodInfo CRDs. Image only, no chart of its own; the tetragon chart deploys it.
image v1.7.1
Security & supply chainstandardApache-2.0