<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SLSA on 黄文卓 | DevOps Engineer</title>
    <link>https://socake.github.io/tags/slsa/</link>
    <description>Recent content in SLSA on 黄文卓 | DevOps Engineer</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-CN</language>
    <managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor>
    <webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster>
    <copyright>© 2026 Wenzhuo Huang</copyright>
    <lastBuildDate>Fri, 05 Dec 2025 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/slsa/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>SLSA 软件供应链等级实施：从 L1 到 L3 的工程化路径</title>
      <link>https://socake.github.io/posts/supply-chain-slsa-framework/</link>
      <pubDate>Fri, 05 Dec 2025 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/supply-chain-slsa-framework/</guid>
      <description>一份 SLSA v1.0 框架的实战落地笔记：讲清楚 Build Track 从 L1 到 L3 的具体要求、用 GitHub Actions 官方 generator 和 Tekton Chains 生成 provenance、用 slsa-verifier 和 Kyverno 做验证、以及和前面 Sigstore/Kyverno/Cosign 的整合。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/supply-chain-slsa-framework/featured.jpg" />
    </item>
    
    <item>
      <title>供应链安全：Trivy 镜像扫描 &#43; Cosign 签名验证实践</title>
      <link>https://socake.github.io/posts/trivy-cosign-supply-chain/</link>
      <pubDate>Sat, 06 Sep 2025 13:50:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/trivy-cosign-supply-chain/</guid>
      <description>你的镜像安全吗？本文梳理容器供应链的主要攻击面，手把手演示 Trivy 扫描、Cosign 签名、K8s 准入控制三层防护的搭建过程，并给出 GitLab CI 集成示例。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/trivy-cosign-supply-chain/featured.jpg" />
    </item>
    
  </channel>
</rss>
