For the complete documentation index, see llms.txt.

SBOM

Image Matcher overview
Learn how the Chainguard Image Matcher uses SBOMs to recommend the closest Chainguard image equivalent for your existing container images.
How to retrieve SBOMs and attestations for Chainguard Containers
How to get SBOM for container images: Chainguard provides Software Bill of Materials for every image - retrieve with Cosign for complete supply chain transparency
Getting started with OpenVEX and vexctl
Using vexctl to manage vulnerability communications
Rego policies
Writing Rego-based policies for Sigstore Policy Controller
Find a matching Chainguard image using the API
How to call the Chainguard Image Matcher API with an existing SBOM to find the closest Chainguard image equivalent.
Example policies
Policy recipes
How to sign an SBOM with Cosign
Signing software bills of materials with Cosign