このコンテンツは選択した言語では利用できません。

Standalone CLIs


Red Hat Advanced Developer Suite - software supply chain 1.8

Explore the standalone CLIs you can use with Red Hat Advanced Developer Suite - software supply chain.

Red Hat Advanced Developer Suite - software supply chain Documentation Team

Abstract

This document provides information about the standalone CLIs you can use with Red Hat Advanced Developer Suite - software supply chain to customize, automate, and secure your software supply chain.

Preface

Several standalone CLIs are available to you as part of Red Hat Advanced Developer Suite - software supply chain through its components and related products.

With the help of the standalone CLIs, you can customize the CI experience, along with automating and securing the process of building and testing your applications. You can enhance the software supply chain security by, for example, running enhanced security checks, signing and verifying your software artifacts, managing compliance with security policies, or generating SBOMs.

You can use these CLI tools with an instance of RHADS - SSC running on an OpenShift cluster, or you can install them on your workstation to build and test your applications locally in a more automated and secure way.

Chapter 1. Overview of Red Hat Advanced Developer Suite - software supply chain standalone CLI programs

You can use five command line interface (CLI) programs as part of Red Hat Advanced Developer Suite - software supply chain (RHADS - SSC) to enhance the security and compliance in your software supply chain.

These standalone CLI programs are shipped with Red Hat products that are either components or dependencies of RHADS - SSC:

To check that a CLI binary is available for your architecture, view Chapter 2. Architectures

1.1. CLI programs available with RHTAS

The binaries of the Cosign, Rekor, and Conforma CLI programs are shipped as components of RHTAS. After you have installed RHTAS, you can download these binaries from the OpenShift cluster by using the OpenShift web console.

Cosign

cosign is a tool for signing container images and verifying the signatures.

Rekor

The rekor tool is a data log that stores metadata of signed software artifacts and provides transparency for signatures of those artifacts. With the Rekor CLI, you can make, verify, and query entries in the Rekor transparency log.

Conforma

Conforma is a tool that enhances security of software supply chains. You can use it to define and enforce security policies for building and testing container images. Conforma is the Red Hat-supported build of the upstream open source project Conforma.

1.2. CLI used with RHTPA

Syft

Syft is a CLI tool for generating Software Bill of Materials (SBOMs) for container images or your local file systems. It provides detailed information about packages, libraries, and dependencies of your software or file systems. Transparency on the software composition helps you secure your software supply chain and manage vulnerabilities.

Syft is distributed as a standalone container image through Red Hat Ecosystem Catalog. The container image is available for AMD64 architecture on Linux.

1.3. CLI used with RHACS

roxctl

roxctl is a CLI for running commands on RHACS. RHADS - SSC pipelines can run three roxctl tasks, including scanning your container images for vulnerabilities and checking the build-time violations of your security policies in container images and YAML deployment files.

Chapter 2. Architectures

Red Hat Advanced Developer Suite - software supply chain (RHADS - SSC) standalone CLI programs are available for these architectures:

Expand
Table 2.1. CLI programs and supported architectures
ArchitecturesCosign, Rekor, Conforma, roxctlSyft

Linux

x86_64

yes

yes

arm64

yes

 

ppc64le

yes

 

s390x

yes

 

MacOS

x86_64

yes

 

arm64

yes

 

Windows

x86_64

yes

 
Note

To use Syft on architectures other than x86_64 on Linux, install the upstream version of Syft.

Revised on 2026-02-04 23:24:20 UTC

Legal Notice

Copyright © Red Hat.
The text of and illustrations in this document are licensed by Red Hat under a Creative Commons Attribution–Share Alike 3.0 Unported license ("CC-BY-SA"). An explanation of CC-BY-SA is available at http://creativecommons.org/licenses/by-sa/3.0/. In accordance with CC-BY-SA, if you distribute this document or an adaptation of it, you must provide the URL for the original version.
Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, Red Hat Enterprise Linux, the Shadowman logo, JBoss, OpenShift, Fedora, the Infinity logo, and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries.
Linux® is the registered trademark of Linus Torvalds in the United States and other countries.
Java® is a registered trademark of Oracle and/or its affiliates.
XFS® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries.
MySQL® is a registered trademark of MySQL AB in the United States, the European Union and other countries.
Node.js® is an official trademark of Joyent. Red Hat Software Collections is not formally related to or endorsed by the official Joyent Node.js open source or commercial project.
The OpenStack® Word Mark and OpenStack logo are either registered trademarks/service marks or trademarks/service marks of the OpenStack Foundation, in the United States and other countries and are used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community.
All other trademarks are the property of their respective owners.
Red Hat logoGithubredditYoutubeTwitter

詳細情報

試用、購入および販売

コミュニティー

Red Hat ドキュメントについて

Red Hat をお使いのお客様が、信頼できるコンテンツが含まれている製品やサービスを活用することで、イノベーションを行い、目標を達成できるようにします。 最新の更新を見る.

多様性を受け入れるオープンソースの強化

Red Hat では、コード、ドキュメント、Web プロパティーにおける配慮に欠ける用語の置き換えに取り組んでいます。このような変更は、段階的に実施される予定です。詳細情報: Red Hat ブログ.

会社概要

Red Hat は、企業がコアとなるデータセンターからネットワークエッジに至るまで、各種プラットフォームや環境全体で作業を簡素化できるように、強化されたソリューションを提供しています。

Theme

© 2026 Red Hat
トップに戻る