
Artifact Signing & SBOM Generation
Complete Artifact Signing & SBOM Generation in a deterministic practice workspace without depending on unavailable host, cloud, hardware, desktop, or multi-node infrastructure.
Briefing
Objectives
- 1Prepare workspace and verify tooling
- 2Prepare local target for Artifact Signing & SBOM Generation
- 3Execute Artifact Signing & SBOM Generation technique
- 4Capture evidence
- 5Complete Key Generator
- 6Complete Image Signer
- 7Tune and interpret
- 8Compile and verify submission
Flags
Submit the verifiable output value for Key Generator as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for Image Signer as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the key finding or status reported by the scan for Vuln Scanner (e.g., open, 200, or version string from local output).
Submit the verifiable output value for Keyless Signer as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the synthesized artifact value for SBOM Creator (e.g., IP 127.0.0.2 or zone name) as verified by dig or cat /etc/bind/.