Artifact Ratification Framework (CNCF Sandbox)
-
Updated
Apr 30, 2026 - Go
Artifact Ratification Framework (CNCF Sandbox)
🥑 Inspect and understand an organization's software supply chain using AI to enable stakeholders to make actionable decisions about software supply chain security
Security working agreements for AI coding agents: hardened AGENTS.md, prompt/tool-injection guardrails, dependency hygiene, Scorecard-ready OSS setup
An example approach to securing containerized workloads within AKS using Notation.
🛠️ A Kaniko-based container builder image for CI pipelines, bundled with Crane, Cosign, Manifest Tool, ORAS, Make, JQ, Bash, and Vault.
Add a description, image, and links to the secure-supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the secure-supply-chain topic, visit your repo's landing page and select "manage topics."