01Cryptographic signature verification for secure build provenance
02Automated rejection of containers with known high/critical CVEs
03Mandatory image digest enforcement to prevent tag mutation attacks
040 GitHub stars
05Registry allowlisting to block untrusted public image sources
06Pre-configured Rego policy templates for rapid Kubernetes implementation