Skip to content
@enterprise-contract

Conforma (formerly Enterprise Contract)

verify artifacts, enforce policies

Engage with the Conforma team by filing an issue in one of the repositories in this GitHub organization.

Our documentation may already have the answer you are looking for.

Note

Conforma was previously known as "Enterprise Contract". Please bear with us as we transition from the old name to the new name, and move our code to its new home in the Conforma GitHub organization.

Pinned Loading

  1. community community Public

    A repo for community utilization

    3

  2. user-guide user-guide Public

    Docs on using Enterprise Contract with Red Hat Trusted Application Pipeline

    Shell 2 12

  3. ec-cli ec-cli Public

    Supply chain artifact verifier and policy checker

    Go 29 33

  4. ec-policies ec-policies Public

    Rego policies for use with Enterprise Contract

    Open Policy Agent 13 32

  5. enterprise-contract-controller enterprise-contract-controller Public

    Defines the Enterprise Contract Policy Kubernetes CRD

    Go 2 16

Repositories

Showing 10 of 21 repositories
  • golden-container Public

    Trivial definition of an image build in compliance with HACBS policy

    enterprise-contract/golden-container’s past year of commit activity
    Dockerfile 1 Apache-2.0 12 1 2 Updated Jan 27, 2025
  • action-validate-image Public

    "Validate" is a robust GitHub Action developed by Enterprise Contract, designed to assess container images for security and compliance. It is made to seamlessly integrate into your CI/CD workflow.

    enterprise-contract/action-validate-image’s past year of commit activity
    1 Apache-2.0 4 1 1 Updated Jan 27, 2025
  • ec-cli Public

    Supply chain artifact verifier and policy checker

    enterprise-contract/ec-cli’s past year of commit activity
    Go 29 Apache-2.0 33 37 21 Updated Jan 27, 2025
  • tekton-catalog Public

    All the Tekton tasks provided by the Enterprise Contract team

    enterprise-contract/tekton-catalog’s past year of commit activity
    Shell 0 Apache-2.0 5 0 0 Updated Jan 27, 2025
  • go-gather Public

    Download files from various sources. Like hashicorp/go-getter but lighter and with less dependencies. (Soon to be) used by ec-cli.

    enterprise-contract/go-gather’s past year of commit activity
    Go 2 Apache-2.0 7 3 3 Updated Jan 25, 2025
  • infra-deployments-ci Public

    Keep infra-deployments updated with the latest Enterprise Contract components

    enterprise-contract/infra-deployments-ci’s past year of commit activity
    Shell 0 Apache-2.0 6 0 0 Updated Jan 25, 2025
  • ec-policies Public

    Rego policies for use with Enterprise Contract

    enterprise-contract/ec-policies’s past year of commit activity
    Open Policy Agent 13 Apache-2.0 32 17 5 Updated Jan 25, 2025
  • config Public

    Preset policy configuration files for Enterprise Contract

    enterprise-contract/config’s past year of commit activity
    Shell 0 6 1 2 Updated Jan 25, 2025
  • user-guide Public

    Docs on using Enterprise Contract with Red Hat Trusted Application Pipeline

    enterprise-contract/user-guide’s past year of commit activity
    Shell 2 12 0 0 Updated Jan 24, 2025
  • .github Public

    Introduce Enterprise Contract

    enterprise-contract/.github’s past year of commit activity
    0 Apache-2.0 4 0 1 Updated Jan 24, 2025