All skills
lukemurraynz avatar

/container-supply-chain

@2cc2455

Production implementation guide for new container image supply-chain security: OCI image signing, digest-first builds, GitHub artifact attestations, Cosign keyless signing, optional Notation/ACR signing, Rekor audit lookup, SBOM generation and attestation, vulnerability scanning, waiver governance, SLSA Build track evidence, deployment admission gates, and artifact-leakage prevention. USE FOR: implementing build-sign-attest-scan-verify pipelines, hardening GHCR or ACR container release workflows, verifying image provenance, configuring Kubernetes/AKS deployment gates, preventing Docker/package artifact leakage, and producing auditable supply-chain records.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/container-supply-chain

This session only. Nothing lands on disk.

CHANGELOG.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Changelog

All notable changes to the container-supply-chain skill.

2.0.1 - 2026-08-02

Added

  • Build context hygiene — .dockerignore placement and depth traps (references/distribution-artifact-leakage.md, Docker and OCI Image Checks). Two production-verified pitfalls from .apm/known-pitfalls.md: (1) .dockerignore must live at the build context root, not the service subdirectory — a monorepo context above the service dir tars up .venv//.git//caches and fails with archive/tar: write too long on ACR remote builds; (2) use **/target (not target) to exclude nested build-artifact dirs (src-tauri/target/, node_modules, dist, .next) that a root-only entry misses.

[Unreleased] - 2026-07-18

AzureFeeds newsletter sweep — incident scenario citations from Microsoft Security blogs.

Added

2.0.0 - 2026-05-28

Phase 2 deep factual freshness audit applied. SLSA, in-toto, Notation, Cosign, and registry-side trust surfaces re-verified against current upstream specs (2026-05-28).

Changed

  • SLSA v1.1 baseline. Reference the SLSA v1.1 specification (published 2024-08) rather than v1.0. The build-track levels (L1-L4) and source-track concepts unchanged at the conceptual level, but the provenance v1 schema field set and the producer-conformance language were tightened.
  • in-toto attestation framework v1.0: predicate types versioned independently of the framework. SBOM predicate (https://spdx.dev/Document / https://cyclonedx.org/bom), provenance predicate (https://slsa.dev/provenance/v1), and vulnerability-scan predicate (https://in-toto.io/attestation/vulns/v0.2) are the current canonical IDs.
  • Notation v1 GA. notation CLI v1.x is the canonical OCI-native signing path for production; the v0.x line is retired. Sign with notation sign --signature-format cose and verify with a trust policy that pins both the certificate identity and the signature algorithm.
  • Cosign keyless via Sigstore remains the preferred path for OSS / public workflows; private workloads should use Notation v1 with an enterprise CA or Cosign with a customer-managed Fulcio.
  • provenance: disabled on multi-arch builds is now treated as a legitimate default rather than a "documented exception" for ACR / Artifact Registry due to upstream BuildKit + registry interop bugs (moby/buildkit#5078). Re-enable per-arch provenance once the registry confirms manifest-list provenance support.

Added

  • Trust-policy worked example for Notation v1 with trustedIdentities pinned to the publishing org's certificate subject and signatureVerification.level set to strict.
  • Registry-side enforcement reference: Sigstore policy-controller and Kyverno verifyImages as the in-cluster trust gate; gh attestation verify on the CI runner is defense-in-depth, not the primary gate.
  • GUAC ingestion pattern for centralised attestation graph: SBOMs, SLSA provenance, and Notation/Cosign signatures flow into a single queryable graph for incident response and compliance evidence.

Verification

  • SLSA specification v1.1 - https://slsa.dev/spec/v1.1 (verified 2026-05-28).
  • in-toto attestation framework v1.0 spec (verified 2026-05-28).
  • Notation v1.x release notes and trust-policy reference (verified 2026-05-28).
  • Sigstore Cosign release notes and keyless flow documentation (verified 2026-05-28).
  • BuildKit issue tracker for multi-arch provenance (moby/buildkit#5078, verified 2026-05-28).

1.0.0 - Initial release

  • Initial skill covering SBOM generation, SLSA provenance, Notation/Cosign signing, attestation verification on the CI runner, and registry-side policy enforcement.

Source: SKILL.md on GitHub

1 alert8d3 checks · Risk CRITICAL
  • Gen Agent Trust Hub8d

    This skill provides production-grade guidance for container supply chain security. It includes an attack surface for indirect prompt injection as it processes external artifacts, and it references a security transparency log that may trigger false positives in generic automated scanners.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
Other metadata
compatibility
Assumes new projects. Prefer current Docker Buildx/build-push-action, Cosign v2+, GitHub artifact attestations, Syft, Grype, Trivy, and OCI registries that support signatures/referrers. Verify current tool versions, CLI flags, registry support, and cloud-provider guidance before enforcement.
metadata
{
  "owner": "platform-engineering",
  "lastReviewed": "2026-07-29",
  "last_verified": "2026-07-29"
}

README badge

README badge for lukemurraynz/hve-agent-skills/container-supply-chain