CNCF [Cloud Native Computing Foundation]
Securing the Supply Chain: A Practical Guide to SLSA Compliance from Build to Runtime
Practical guide to securing software supply chain using CNCF tools. Covers SLSA compliance, GitHub Actions, Cosign, Kyverno, in-toto, and Kubescape for build-to-runtime security in Kubernetes ecosystems.