4/1/2022
•
EN
OCI as attestations storage for your packages
Explains using OCI registries to store SBOMs and build provenance for non-Docker packages like npm, using Cosign for security.