References
Originally published in Japanese at https://zenn.dev/ymotongpoo/books/chainguard-image-toolchain/viewer/99-references.
The resources referenced while writing this book, in the order chapters introduce them.
Repositories and official documentation
- chainguard-dev/melange
- melange CLI reference (melange_build.md)
- melange CLI reference (melange.md)
- Chainguard Academy: melange overview
- Chainguard Academy: Getting started with melange
- wolfi-dev/os
- chainguard-dev/apko
- apko: apko_file.md
- apko: build-process.md
- apko: sbom-composition.md
- Chainguard Academy: apko
- chainguard-dev/rules_apko
- chainguard-images (GitHub organization)
- melange golden file (sed-4.9-r8.spdx.json)
- melange examples/test-xcover.yaml
- wolfi-dev/os wolfi-base.yaml
- s6
- just-containers/s6-overlay
- melange pkg/build/pipelines
- melange examples/go-build.yaml
- anchore/syft binary cataloger
- grafana/xk6 Dockerfile
Blog posts and articles
- Introducing: Chainguard, Inc. (Chainguard Unchained)
- About Chainguard
- Reimagining the Linux distro with Wolfi (Chainguard Unchained)
- Secure your software factory with melange and apko (Chainguard Unchained)
- 2021 State of the Software Supply Chain (Sonatype)
Other
- GoogleContainerTools/distroless
- SLSA (Supply-chain Levels for Software Artifacts)
- CISA: Software Bill of Materials (SBOM)
- google/go-containerregistry
- ED 21-01: Mitigate SolarWinds Orion Code Compromise (CISA)
- Apache Log4j Security Vulnerabilities
- Executive Order 14028: Improving the Nation’s Cybersecurity (Federal Register)