DirectorySecurity advisories
Sign in

Directory

sigstore-scaffolding-getoidctoken-fips logoFIPS

sigstore-scaffolding-getoidctoken-fips

Last changed
Sign in for updates

Get notified of upcoming product changes, critical vulnerability notifications and patches and more.

Sign in
Versions
Overview
Provenance
Specifications
SBOM
Vulnerabilities
Advisories

Minimal Wolfi-based Sigstore images.

Download this Image

The image is available on cgr.dev:

docker pull cgr.dev/chainguard/sigstore-scaffolding:latest

The images in this directory are just the "glue" for bootstrapping the stack, but Chainguard offers minimal images for each of the elements needed by the Sigstore "scaffold" Helm chart for bootstrapping a full sigstore stack.

In addition to these images, the stack also pulls in images from:

The stack also pulls in several support images:

  • curl
  • netcat
  • redis
  • (NYI) mysql - Currently sigstore relies on the nearly EOL mysql 5.7

To see an example of how we substitute images into the scaffold Helm chart's values.yaml see our values.tf example.

Licenses

Chainguard Images contain software packages that are direct or transitive dependencies. The following licenses were found in the "latest" version of this image:

  • Apache-2.0

  • LGPL-2.1-or-later

  • MIT

  • MPL-2.0

For a complete list of licenses, please refer to this Image's SBOM.

Software license agreement

Compliance

This is a FIPS validated image for FedRAMP compliance.

This image is STIG hardened and scanned against the DISA General Purpose Operating System SRG with reports available.

Learn more about STIGsGet started with STIGs

Related images

Category
FIPS
STIG
application
sigstore
tools

Products

Chainguard Images

© 2024 Chainguard, Inc.