Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.9 KiB

API Reference: Implementing Image Provenance Verification with Cosign

Cosign CLI Commands

# Sign image (keyless with OIDC)
cosign sign --yes IMAGE_REF

# Sign with key
cosign sign --key cosign.key IMAGE_REF

# Verify (keyless)
cosign verify --certificate-identity USER --certificate-oidc-issuer ISSUER IMAGE_REF

# Verify with key
cosign verify --key cosign.pub IMAGE_REF

# Attach attestation
cosign attest --predicate sbom.json --type spdxjson IMAGE_REF

# Verify attestation
cosign verify-attestation --type spdxjson IMAGE_REF

# Get signature location
cosign triangulate IMAGE_REF

Sigstore Components

Component Purpose
Cosign Sign and verify images
Fulcio Short-lived certificate authority
Rekor Transparency log
policy-controller Kubernetes admission

Attestation Types

Type Predicate Use Case
custom Custom JSON General
spdxjson SPDX SBOM Software bill of materials
cyclonedxjson CycloneDX SBOM Alt SBOM format
slsaprovenance SLSA Provenance Build provenance
vuln Vulnerability scan Scan results

Kyverno Policy (Kubernetes Admission)

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: verify-images
spec:
  validationFailureAction: Enforce
  rules:
    - name: verify-cosign
      match:
        any:
          - resources: { kinds: [Pod] }
      verifyImages:
        - imageReferences: ["ghcr.io/org/*"]
          attestors:
            - entries:
                - keyless:
                    subject: "*@org.com"
                    issuer: "https://token.actions.githubusercontent.com"

References