SBOM
Image Matcher overview
Learn how the Chainguard Image Matcher uses SBOMs to recommend the closest Chainguard image equivalent for your existing container images.
How to retrieve SBOMs and attestations for Chainguard ContainersHow to get SBOM for container images: Chainguard provides Software Bill of Materials for every image - retrieve with Cosign for complete supply chain transparency
Getting started with OpenVEX and vexctlUsing vexctl to manage vulnerability communications
Rego policiesWriting Rego-based policies for Sigstore Policy Controller
Find a matching Chainguard image using the APIHow to call the Chainguard Image Matcher API with an existing SBOM to find the closest Chainguard image equivalent.
Example policiesPolicy recipes
How to sign an SBOM with CosignSigning software bills of materials with Cosign