Hardening Container Supply Chains: Cosign Signatures and SBOM Attestations
Securing Docker container images with cryptographic keyless signatures using Sigstore Cosign and CycloneDX SBOM generation in CI/CD.
Cloud security, IAM, zero-trust architecture, Workload Identity Federation, and network security. (2 published articles)
Securing Docker container images with cryptographic keyless signatures using Sigstore Cosign and CycloneDX SBOM generation in CI/CD.
Eliminate vulnerable service account JSON keys using OpenID Connect (OIDC) token exchange between Azure DevOps and Google Cloud IAM.