Procedural
How to sign an SBOM with Cosign
Signing software bills of materials with Cosign
Adding custom certificates with Custom AssemblyHow to add custom certificates to customized images with Custom Assembly.
Create an assumable identity for a Bitbucket pipelineProcedural tutorial outlining how to create a Chainguard identity that can be assumed by a Bitbucket workflow.
How to verify file signatures with CosignUse Cosign to verify non-container software artifacts
Use chainctl to create an assumable identity for a Jenkins pipelineHow to use chainctl to create a Chainguard identity that can be assumed by a Jenkins pipeline.
How to pull packages from Chainguard package repositories through NexusTutorial for setting up Sonatype Nexus raw repositories as pull-through caches for apk packages from Chainguard's package repositories.
Verifying signatures in air-gapped environmentsUse Cosign to verify container signatures and attestations without outbound network access