Blog

Validating arbitrary data

Posted on February 11, 2026

In this tutorial we’ll introduce some basic Conforma concepts and look at examples where Conforma is used to apply policy checks against arbitrary input data. We often use the ec validate image command, which fetches and verifies an image’s SLSA provenance attestations, then applies policy checks against them. But Conforma can work just as well with any kind of input using the ec validate input command, and in fact that is a useful way to demonstrate some Conforma ideas and techniques.

Introducing Our Comprehensive Resources Page

Posted on July 23, 2025

Whether you’re just getting started with supply chain security or looking to deepen your understanding of policy enforcement in container workflows, we’ve curated a comprehensive collection of resources to help you on your journey.

We’ve organized all our educational content, like conference presentations, demos, and expert talks, into our new Resources page for easy access and reference.

Policies Polyglot: Evaluating Custom Predicates

Posted on March 20, 2024

Attestations are a wonderful way to attach metadata to container images in a secure manner. One of the most popular formats is SLSA Provenance which is used to provide information on how the image was created. Our Hitchhiker’s Guide demonstrates how to write policies to assert the contents of the SLSA Provenance. Here, we expand on that approach to assert the contents of any attestation format, even completely made up ones.