In December, I published a post on securing the container supply chain โ SBOM generation, image signing, and build provenance with GitHub Actions. That covered build-time security: making sure the image you ship is the image you built.
But what โฆ