CtrlK
BlogDocsLog inGet started
Tessl Logo

nitinjain999/platform-skills

Production-grade platform engineering handbook — Kubernetes, Terraform, Flux CD, GitHub Actions, AWS, and more.

67

Quality

84%

Does it follow best practices?

Impact

No eval scenarios have been run

SecuritybySnyk

Passed

No known issues

Overview
Quality
Evals
Security
Files

README.mdexamples/supply-chain/

Supply Chain Security Examples

Status: Stable

Working examples for the /platform-skills:supply-chain skill.

Files

FileDescription
sign-and-push.yamlGitHub Actions: build, sign with Cosign keyless, and push
sbom-attest.yamlGitHub Actions: generate SBOM with Syft and attest
trivy-gate.yamlGitHub Actions: Trivy CVE scan with CRITICAL+HIGH severity gate
kyverno-verify-image.yamlKyverno ImageValidatingPolicy: block unsigned images
slsa-provenance.yamlGitHub Actions: SLSA Level 2 provenance via slsa-github-generator

Usage

Copy the relevant file into your .github/workflows/ or policies/ directory and substitute <org> and <image> placeholders.

Validation

bash examples/supply-chain/supply-chain-validate.sh

examples

BEFORE_AFTER.md

CHANGELOG.md

CODE_OF_CONDUCT.md

COMMANDS.md

CONTRIBUTING.md

EDITOR_INTEGRATIONS.md

GETTING_STARTED.md

HOW_IT_WORKS.md

install.sh

INSTALLATION.md

LAUNCH.md

PROMPTS.md

QUICKSTART.md

README.md

renovate.json

SECURITY.md

SKILL.md

tessl.json

tile.json