How-to and operational guides for the cssc-framework repository, organized
around the CSSC framework stages. Within each stage, guides are grouped
under two cross-cutting themes where they apply: Authenticity and Integrity
and Supply Chain Observability.
- Acquire — mirroring base images from Docker Hub into GHCR.
- Catalog — promotion overrides and approvals for quarantined images.
- Build — image tagging, annotations, and attestations for the demo app images.
- Deploy — deploying the demo apps.
- Run — running the applications.
- Observability — querying the supply-chain graph (artifact
lineage, base images, tag history) through the
cssc-graphCLI and thegraph-serviceAPI. Cross-cutting across stages.