Policies
Documentation and resources relating to policies in Sigstore Policy Controller.
Enforce SBOM attestation with Policy Controller
Disallowing Non-Default Capabilities
Disallowing Privileged Pods
Disallowing Run as Root User
Maximum Container Image Age
Disallowing Unsafe sysctls
Verify Signed Chainguard Images
Limit High or Critical CVEs in your Images Workloads
Rego Policies
Example Policies