Skip to main content
RunBook Academy

automation · security · cloud

Git, CI/CD & GitOps for Infrastructure Engineers

A production-focused course that takes infrastructure, platform, and operations engineers from Git fundamentals to operating production CI/CD pipelines and GitOps-driven deployment for business-critical infrastructure. Covers the Git object model, branching strategies, recovery, signing and history rewriting, GitHub Actions as the primary CI platform (with GitLab CI and Jenkins as architectural comparisons), runners, OIDC federation, artifact immutability, supply-chain security with Cosign and Sigstore, SLSA provenance, Argo CD as the primary GitOps controller (with Flux as architectural comparison), drift detection, reconciliation, break-glass procedures, incident response, and a complete production delivery capstone.

Who this is for

  • Systems administrators moving into infrastructure-as-code and GitOps
  • Infrastructure engineers responsible for business-critical delivery pipelines
  • Platform engineers designing production CI/CD and deployment systems
  • DevOps engineers owning the end-to-end change pipeline
  • SREs operating production infrastructure through declarative state
  • Cloud engineers integrating cloud delivery with on-premises systems
  • Security engineers reviewing CI/CD supply-chain controls
  • Technical professionals responsible for source control and delivery governance

Prerequisites

  • Comfortable on a Linux command line
  • Familiar with infrastructure concepts (operating systems, networking, storage)
  • Have edited configuration files and run shell commands against production
  • Some exposure to YAML, JSON, and at least one configuration-management or IaC tool

Other RunBook Academy courses

  • Linux — required. Every tool in this course - Git itself, the runner host, every CI pipeline shell block, every GitOps controller - runs on Linux. The Linux course covers the depth (shell, systemd, networking, permissions, secrets, package management) that this course assumes.
  • Docker & Containers — recommended. Containers are the dominant build artefact and the dominant runtime in modern CI/CD and GitOps. The Docker course covers image construction, registries, runtime security, and supply chain basics that this course then operates against.
  • Ansible — recommended. Ansible is one of the major IaC tools that this course teaches a delivery pipeline for. The Ansible course covers the playbook model, idempotency, secrets, and Molecule that the Ansible CI chapter builds on.
  • Terraform — recommended. Terraform is the dominant declarative infrastructure tool. The Terraform course covers state, plan, modules, providers, and policy that the Terraform CI and supply-chain chapters build on.
  • Kubernetes — recommended. Kubernetes is the dominant application deployment target for GitOps. The Kubernetes course covers the API, reconciliation, RBAC, and workloads that the Kubernetes CI and Argo CD / Flux chapters assume.
  • Observability — recommended. Deployment markers, telemetry correlation, and CI/CD observability all build on the metrics, logs, and traces foundation. The Observability course covers Prometheus, Grafana, Loki, Tempo, and OTel that this course integrates with.

Choose a learning path

The complete course remains a reference library. These paths identify the ordered reading and required practice needed for a specific role; content outside a path is optional reference material.

Required core

Core Sysadmin path

~70 h

The required 70-hour route: safe Git operations and recovery, CI runner and credential operations, immutable delivery, baseline GitOps, and incident response. The remaining curriculum is reference or specialization material.

24 curriculum parts
  1. I · Version Control Foundations
  2. II · Git Architecture
  3. VII · Repository Inspection
  4. X · Merge Conflicts
  5. XIV · Revert
  6. XVII · Reflog
  7. XVIII · Git Recovery
  8. XXVII · Infrastructure Repository Architecture
  9. XXX · Pull Requests and Merge Requests
  10. XXXII · Protected Branches
  11. XXXV · Secrets in Git
  12. XXXVII · CI Fundamentals
  13. XL · Runners
  14. XLI · Runner Security
  15. XLII · CI Secrets
  16. XLIII · OIDC and Short-Lived Credentials
  17. XLV · Artifact Immutability
  18. LXI · Pipeline Failure Handling
  19. LXXII · GitOps Foundations
  20. LXXIV · Reconciliation
  21. LXXV · Drift
  22. LXXXI · Synced versus Healthy
  23. LXXXV · GitOps Rollback
  24. LXXXVII · GitOps During Incidents
12 required practice gates

Optional specialization

Git deep dive

~50 h

Git objects, graphs, history manipulation, recovery, repository scaling, signing, and shared-history policy for administrators who own source-control workflows.

20 curriculum parts
  1. III · Git Objects
  2. IV · Commit Graph and History
  3. V · Branches, Refs and HEAD
  4. VI · Index / Staging Area
  5. VIII · Branching
  6. IX · Merging
  7. XI · Rebasing
  8. XII · Merge vs Rebase
  9. XIII · Cherry-Pick
  10. XV · Reset
  11. XVI · Restore and Switch
  12. XIX · Tags and Releases
  13. XX · Remotes
  14. XXI · Fetch vs Pull
  15. XXII · Force Push
  16. XXIII · Worktrees
  17. XXIV · Bisect
  18. XXXIII · Commit and Tag Signing
  19. XXXVI · Git History Rewriting
  20. CII · Large Repository Performance
6 required practice gates

Optional specialization

CI platform operator

~58 h

Pipeline architecture, runners, credentials, caching, observability, capacity, disaster recovery, and infrastructure delivery operations.

20 curriculum parts
  1. XXXVIII · CI Architecture
  2. XXXIX · Pipelines
  3. XL · Runners
  4. XLI · Runner Security
  5. XLII · CI Secrets
  6. XLIII · OIDC and Short-Lived Credentials
  7. XLVI · Caching
  8. XLVII · Pipeline Dependencies
  9. XLIX · Infrastructure CI
  10. L · Terraform CI
  11. LI · Ansible CI
  12. LII · Kubernetes CI
  13. LIII · Container CI
  14. LXI · Pipeline Failure Handling
  15. LXII · Concurrency
  16. LXIII · CI/CD Observability
  17. XCVII · CI/CD Disaster Recovery
  18. XCVIII · Git Hosting Failure
  19. C · Runner Capacity
  20. CI · Pipeline Performance
8 required practice gates

Optional specialization

Supply-chain security

~45 h

OIDC, immutable artifacts, dependency pinning, SBOMs, signing, provenance, policy, secrets, and incident response for delivery systems.

18 curriculum parts
  1. XXXIII · Commit and Tag Signing
  2. XXXIV · Git Security
  3. XXXV · Secrets in Git
  4. XLIII · OIDC and Short-Lived Credentials
  5. XLV · Artifact Immutability
  6. LXV · Software Supply Chain Security
  7. LXVI · Third-Party Actions and Plugins
  8. LXVII · Dependency Pinning
  9. LXVIII · SBOM
  10. LXIX · Artifact Signing
  11. LXX · Provenance
  12. LXXI · CI/CD Threat Modelling
  13. LXXXIX · Repository Security
  14. XC · CI Platform Security
  15. XCI · Least Privilege CI/CD
  16. XCIV · Incident: Secret Leak
  17. XCV · Incident: Compromised Runner
  18. XCVI · Incident: Malicious Dependency
6 required practice gates

Optional specialization

GitOps and Kubernetes operator

~50 h

Reconciliation, drift, Argo CD and Flux, promotion, secrets, RBAC, rollback, multi-cluster operations, and controller recovery.

17 curriculum parts
  1. LXXII · GitOps Foundations
  2. LXXIII · Push versus Pull Deployment
  3. LXXIV · Reconciliation
  4. LXXV · Drift
  5. LXXVI · GitOps Repository Architecture
  6. LXXVII · Argo CD
  7. LXXVIII · Flux
  8. LXXIX · Sync Strategies
  9. LXXX · GitOps Pruning
  10. LXXXI · Synced versus Healthy
  11. LXXXII · GitOps Secrets
  12. LXXXIII · GitOps RBAC
  13. LXXXIV · Environment Promotion
  14. LXXXV · GitOps Rollback
  15. LXXXVI · GitOps Failure Modes
  16. LXXXVII · GitOps During Incidents
  17. LXXXVIII · Infrastructure GitOps
7 required practice gates

What you'll be able to do

After completing this course, you should be capable of independently:

  • Use Git fluently at the object, graph, and workflow level
  • Choose and defend a branching and merge strategy for an infrastructure repository
  • Recover from destructive Git operations using reflog and history-rewriting tools
  • Sign commits and tags with GPG or SSH keys and verify signatures
  • Design a repository layout for Terraform, Ansible, Kubernetes, and configuration code
  • Configure branch protection, CODEOWNERS, and required status checks
  • Detect, rotate, and clean secrets committed to Git history
  • Design and operate a production CI/CD pipeline on GitHub Actions
  • Compare GitHub Actions with GitLab CI and Jenkins architecturally
  • Configure runners - hosted, self-hosted, ephemeral - with least privilege
  • Authenticate CI workloads to cloud platforms with OIDC federation and short-lived credentials
  • Build, sign, verify, and promote immutable OCI artefacts
  • Generate and consume SBOMs and SLSA provenance
  • Pin dependencies by digest across actions, containers, providers, modules, and packages
  • Threat-model CI/CD systems and detect supply-chain compromises
  • Choose, configure, and operate a GitOps controller (Argo CD primarily, Flux architecturally)
  • Reason about reconciliation, drift, pruning, self-heal, and break-glass procedures
  • Roll back production changes safely across application, Kubernetes, Terraform, and configuration boundaries
  • Distinguish Synced from Healthy, and diagnose GitOps failure modes
  • Reconstruct any historical deployment (commit, pipeline, artefact, approver, environment, tests)
  • Operate CI/CD during incidents: secret leaks, compromised runners, malicious dependencies, registry outages, hosting outages
  • Design a capstone production delivery environment and complete its phase-two execution evidence with ten injected incidents

Curriculum overview

124 planned parts · 716 lessons currently published.

Part I

Version Control Foundations

Purpose of version control; snapshots, history, collaboration, reproducibility, auditability, and the infrastructure-as-code implications.

6 lessons

Part II

Git Architecture

Working tree, index, repository, objects, refs, plumbing vs porcelain commands.

6 lessons

Part III

Git Objects

Blob, tree, commit, tag, OIDs, content-addressed storage, plumbing commands.

6 lessons

Part IV

Commit Graph and History

Parent relationships, DAG, ancestry, history traversal with git log.

6 lessons

Part V

Branches, Refs and HEAD

Branch pointers, references namespace, HEAD, detached HEAD state.

6 lessons

Part VI

Index / Staging Area

Working tree to index to repository, partial staging, interactive add.

6 lessons

Part VII

Repository Inspection

git status, git log, git show, git diff in all their forms.

6 lessons

Part VIII

Branching

Branch creation, switching, divergence, collaboration patterns.

6 lessons

Part IX

Merging

Fast-forward, three-way merge, merge commits, octopus merge.

6 lessons

Part X

Merge Conflicts

Realistic Terraform, Ansible, Kubernetes, YAML conflict resolution.

6 lessons

Part XI

Rebasing

Rebase mechanics, commit replay, interactive rebase, history rewriting.

6 lessons

Part XII

Merge vs Rebase

Trade-offs, when to use which, team policy.

6 lessons

Part XIII

Cherry-Pick

Backporting, hotfixes, duplicated-history implications.

6 lessons

Part XIV

Revert

Safe history-preserving reversal of changes.

6 lessons

Part XV

Reset

Soft, mixed, hard reset modes and destructive consequences.

6 lessons

Part XVI

Restore and Switch

Modern Git command separation introduced in Git 2.23.

6 lessons

Part XVII

Reflog

Recovery of reset commits, rebases, deleted branches, lost HEAD positions.

6 lessons

Part XVIII

Git Recovery

Realistic recovery workflows for lost work.

6 lessons

Part XIX

Tags and Releases

Lightweight, annotated, signed tags; release workflows.

6 lessons

Part XX

Remotes

Fetch, push, remote tracking branches, upstream relationships.

6 lessons

Part XXI

Fetch vs Pull

What each command actually does, when to use which.

6 lessons

Part XXII

Force Push

--force vs --force-with-lease, reflog-based safety, Production Warning.

6 lessons

Part XXIII

Worktrees

.git/worktrees mechanism, multiple working trees, infrastructure use cases.

6 lessons

Part XXIV

Bisect

Root-cause analysis to find the breaking infrastructure commit.

6 lessons

Part XXV

Hooks

Client-side, server-side hooks; limitations and enforcement boundaries.

6 lessons

Part XXVI

Git Configuration

Scopes (system/global/local/worktree), identity, signing configuration.

6 lessons

Part XXVII

Infrastructure Repository Architecture

Layout for Terraform, Ansible, Kubernetes, network, policy, documentation repos.

6 lessons

Part XXVIII

Monorepo vs Multi-Repo

Ownership, blast radius, CI performance, access control, dependencies.

6 lessons

Part XXIX

Branching Strategies

Trunk-based, short-lived branches, release branches, GitFlow contextually.

6 lessons

Part XXX

Pull Requests and Merge Requests

Review, diff, approvals, status checks, ownership, change reasoning.

6 lessons

Part XXXI

CODEOWNERS and Ownership Controls

Path-based ownership, required reviewers, bypass risks.

6 lessons

Part XXXII

Protected Branches

Direct-push restrictions, approvals, status checks, bypass risks.

6 lessons

Part XXXIII

Commit and Tag Signing

GPG and SSH signing for production verifiability.

6 lessons

Part XXXIV

Git Security

SSH, HTTPS tokens, credential storage, permissions, compromised accounts.

6 lessons

Part XXXV

Secrets in Git

Removing from current file does not remove from history; detection, rotation, cleanup.

6 lessons

Part XXXVI

Git History Rewriting

git filter-repo, BFG, scrubbing, re-signing, force-push blast radius.

6 lessons

Part XXXVII

CI Fundamentals

Commit to trigger to runner to job to steps to result.

6 lessons

Part XXXVIII

CI Architecture

Control plane, runners, jobs, environments, artifacts, caches, credentials.

6 lessons

Part XXXIX

Pipelines

Stages, jobs, dependencies and parallelism semantics.

6 lessons

Part XL

Runners

Hosted, self-hosted, ephemeral, persistent, isolation models.

6 lessons

Part XLI

Runner Security

Threat model: arbitrary code, production credentials, Docker socket, privileged containers.

6 lessons

Part XLII

CI Secrets

Secret variables, masking limitations, log leakage, environment scope.

6 lessons

Part XLIII

OIDC and Short-Lived Credentials

OIDC federation from CI to cloud, no long-lived production credentials.

6 lessons

Part XLIV

Artifacts

Build outputs, Terraform plans, packages, reports, images, manifests.

6 lessons

Part XLV

Artifact Immutability

Build once, promote the same artifact across environments.

6 lessons

Part XLVI

Caching

Performance plus cache-poisoning and stale-cache risks; cache versus artifact.

6 lessons

Part XLVII

Pipeline Dependencies

Actual DAG and stage semantics of the primary CI platform.

6 lessons

Part XLVIII

Conditional Execution

Branch, path, tag, environment conditions, expressions, matrix.

6 lessons

Part XLIX

Infrastructure CI

Format, lint, static analysis, security, tests, plan/diff, review.

6 lessons

Part L

Terraform CI

fmt, validate, lint, security, tests, plan-as-artifact, reviewed plan.

6 lessons

Part LI

Ansible CI

YAML lint, ansible-lint, syntax checks, Molecule, staged validation.

6 lessons

Part LII

Kubernetes CI

Manifests, Helm and Kustomize validation, policy, security scans.

6 lessons

Part LIII

Container CI

Build, tests, SBOM, scanning, signing, immutable digests.

6 lessons

Part LIV

Infrastructure Testing Strategy

Static, unit, integration, staging, production validation.

6 lessons

Part LV

Continuous Delivery versus Continuous Deployment

The actual distinction and when each fits.

6 lessons

Part LVI

Deployment Environments

Development, test, staging, production, identity isolation.

6 lessons

Part LVII

Approval Gates

When human approval adds safety and when it adds bureaucracy.

6 lessons

Part LVIII

Deployment Strategies

Rolling, canary, blue/green, recreate.

6 lessons

Part LIX

Rollback

Per-artifact rollback across containers, Kubernetes, Terraform, configuration, databases.

6 lessons

Part LX

Forward Fix versus Rollback

Operational decision-making between the two.

6 lessons

Part LXI

Pipeline Failure Handling

Retries, cleanup, partial deployment, resumability, idempotency.

6 lessons

Part LXII

Concurrency

Concurrent deployments, environment locking, Terraform state locks, serialization.

6 lessons

Part LXIII

CI/CD Observability

Queue duration, runtime, success/failure, flaky jobs, deployment success metrics.

6 lessons

Part LXIV

Auditability

Which commit, pipeline, artifact, approver, environment, tests, deployment.

6 lessons

Part LXV

Software Supply Chain Security

Source, dependencies, CI, artifact, registry, deployment as trust boundaries.

6 lessons

Part LXVI

Third-Party Actions and Plugins

Mutable references, compromised maintainers, abandoned projects, unexpected updates.

6 lessons

Part LXVII

Dependency Pinning

Actions, plugins, containers, providers, modules, collections, packages.

6 lessons

Part LXVIII

SBOM

Purpose, generation (syft, cyclonedx-bom, actions/attest), consumption.

6 lessons

Part LXIX

Artifact Signing

Cosign v3 keyless signing, Fulcio, Rekor, Bundle format.

6 lessons

Part LXX

Provenance

Where did this artifact come from; SLSA v1.2 Build track.

6 lessons

Part LXXI

CI/CD Threat Modelling

Malicious commit, account compromise, dependency compromise, runner compromise, secret leakage, artifact substitution, registry compromise.

6 lessons

Part LXXII

GitOps Foundations

Git to desired state to reconciliation controller to environment to drift detection.

6 lessons

Part LXXIII

Push versus Pull Deployment

Trust differences between CI pushing and controller pulling.

6 lessons

Part LXXIV

Reconciliation

Continuously reconciling Git desired state to actual cluster state.

6 lessons

Part LXXV

Drift

Manual, accidental, emergency changes; reconciliation, alerting on drift.

6 lessons

Part LXXVI

GitOps Repository Architecture

Application repos, environment repos, monorepo vs multi-repo, overlays, promotion.

6 lessons

Part LXXVII

Argo CD

Application, source, destination, sync, health, projects, RBAC, repositories, ApplicationSets.

6 lessons

Part LXXVIII

Flux

GitRepository, Kustomization, HelmRelease, OCIRepository, image automation, notifications.

6 lessons

Part LXXIX

Sync Strategies

Manual sync, automated sync, self-heal, pruning - per controller capability.

6 lessons

Part LXXX

GitOps Pruning

Desired-state deletion and blast radius; Production Warning.

6 lessons

Part LXXXI

Synced versus Healthy

Reconciliation is not the same as application health.

6 lessons

Part LXXXII

GitOps Secrets

External secret systems, encrypted Git workflows, secret references.

6 lessons

Part LXXXIII

GitOps RBAC

Repository permissions, controller permissions, cluster access, environment boundaries.

6 lessons

Part LXXXIV

Environment Promotion

Development, test, staging, production with immutable artifact promotion.

6 lessons

Part LXXXV

GitOps Rollback

git revert is not the same as data rollback.

7 lessons

Part LXXXVI

GitOps Failure Modes

Repository unavailable, auth failure, controller unavailable, bad manifests, unhealthy deployment, prune incident, secret dependency failure.

6 lessons

Part LXXXVII

GitOps During Incidents

Pragmatic break-glass: incident, emergency change, restore, document, update Git, restore reconciliation.

6 lessons

Part LXXXVIII

Infrastructure GitOps

Beyond simple application deployment where tooling actually supports it.

6 lessons

Part LXXXIX

Repository Security

MFA, access control, branch protection, signing, ownership, audit.

6 lessons

Part XC

CI Platform Security

What CI can access: cloud, Kubernetes, Terraform state, registries, secret stores, production networks.

6 lessons

Part XCI

Least Privilege CI/CD

Validation identity is not the production deployment identity.

6 lessons

Part XCII

Protected Environments

Platform mechanisms for production environment protection.

6 lessons

Part XCIII

Credential Rotation

Deploy keys, tokens, cloud credentials, registry credentials, GitOps credentials.

6 lessons

Part XCIV

Incident: Secret Leak

Response order - revoke/rotate first, assess exposure, inspect usage, remove repo exposure, audit, prevent recurrence.

6 lessons

Part XCV

Incident: Compromised Runner

Isolation, credential revocation, artifact impact analysis, job history, clean rebuild.

6 lessons

Part XCVI

Incident: Malicious Dependency

Stop builds, identify impacted artifacts, rotate credentials, rebuild trusted artifacts, improve controls.

6 lessons

Part XCVII

CI/CD Disaster Recovery

Recovery of CI configuration, runners, secrets, artifact registry, deployment process.

6 lessons

Part XCVIII

Git Hosting Failure

Continuity options and limitations.

7 lessons

Part XCIX

Artifact Registry Failure

Impact on deployment and recovery.

6 lessons

Part C

Runner Capacity

Queueing, concurrency, ephemeral runner sizing, autoscaling.

6 lessons

Part CI

Pipeline Performance

Optimisation only after measurement.

6 lessons

Part CII

Large Repository Performance

Binaries, Git LFS, shallow/partial clones, repository design.

6 lessons

Part CIII

Infrastructure Repository Anti-Patterns

Committed secrets, Terraform state in Git, generated files, no ownership, direct production pushes, mutable dependencies.

6 lessons

Part CIV

CI/CD Anti-Patterns

Permanent privileged runners, secrets in logs, mutable dependencies, no artifact identity, rebuilding per environment, unsafe automatic apply.

6 lessons

Part CV

GitOps Anti-Patterns

Cluster-admin everywhere, unsafe prune, plaintext secrets, uncontrolled drift, no environment separation.

6 lessons

Part CVI

Change Management

Every infrastructure change answers: what, why, which commit, which environment, which artifact, what validation, what blast radius, what rollback, who owns it.

6 lessons

Part CVII

Production Infrastructure Delivery Architecture

Reference diagram of engineer to Git to pull request to CI to artifact to approval to GitOps to production.

6 lessons

Part CVIII

Infrastructure-as-Code Integration

How Terraform, Ansible, Kubernetes, Docker, networking pipelines connect.

6 lessons

Part CIX

Terraform Delivery Pipeline

End-to-end Terraform delivery: lint, validate, scan, plan, review, apply, drift, audit.

6 lessons

Part CX

Ansible Delivery Pipeline

End-to-end Ansible delivery: lint, syntax, Molecule, staged validation, idempotency.

6 lessons

Part CXI

Kubernetes Delivery Pipeline

CI plus GitOps for Kubernetes workloads.

6 lessons

Part CXII

Container Delivery Pipeline

Source, test, build, SBOM, scan, sign, registry, deploy.

6 lessons

Part CXIII

Observability Integration

Deployment-event correlation across metrics, logs, traces.

6 lessons

Part CXIV

Deployment Markers

Deployment, telemetry annotation/event, performance/error change correlation.

6 lessons

Part CXV

Production Operating Model

Responsibilities among application, platform, infrastructure, security, reviewers.

6 lessons

Part CXVI

Governance Without Bureaucracy

Controls that improve safety without meaningless approval chains.

6 lessons

Part CXVII

Compliance and Audit

Reconstruction: who, what, why, which commit, artifact, pipeline, tests, environment.

6 lessons

Part CXVIII

Final Reference Architecture

Complete production-quality reference: Git, CI control plane, ephemeral runners, artifact registry, secret manager, short-lived identities, GitOps controllers, environments, observability, audit.

6 lessons

Part Labs

Labs

Hands-on disposable-environment labs covering Git plumbing, conflict resolution, recovery, CI/CD pipeline construction, supply-chain tooling, GitOps controller installation, drift, rollback, and incident response.

0 lessons

Part Runbooks

Runbooks

Operational procedures for Git recovery, CI failure triage, runner restoration, secret leak response, GitOps reconciliation, environment promotion, and supply-chain compromise.

0 lessons

Part Checklists

Checklists

Production readiness reviews for repositories, pipelines, runners, supply chains, artifacts, deployments, GitOps, secrets, rollback, and DR.

0 lessons

Part Breakfix

Break/Fix Scenarios

Evidence-first diagnosis of Git, CI/CD, and GitOps failure modes (recovery, secrets, runner, dependency, environment, prune, reconcile).

0 lessons

Part Capstone

Production Capstone

A complete production infrastructure delivery environment with ten injected incidents.

0 lessons

Part Final

Final Assessment

Final theory assessment plus final practical assessment of an inherited delivery environment.

6 lessons

Verified against

  • Gitv2.55.x teaching target; 2.40+ minimum· released 2026-06-29· verified 2026-08-25
  • GitHub Actionsvcontinuous service; Aug 2026 documentation baseline· released 2026-08-01· verified 2026-08-25
  • Argo CDvv3.5.x teaching target; v3.0+ minimum· released 2026-08-04· verified 2026-08-25
  • Fluxvv2.9.x· released 2026-06-30· verified 2026-08-25
  • Sigstore Cosignvv3.1.x· released 2026-08-06· verified 2026-08-25
  • SLSAvv1.2· released 2025-04· verified 2026-08-20
  • OCI Distribution Specificationvv1.1· verified 2026-08-20
  • Git LFSvv3.7.1· released 2025-11-04· verified 2026-08-20
  • Kubernetes (cross-course target)v1.36.x· verified 2026-08-26