Cosign signatures
Every bundle ships with a .cosign.bundle sidecar. Keyless OIDC-federated identity verifies build provenance.
Distribution portal · downloads.autonomize.ai
This portal distributes signed Genesis bundles to our enterprise customers. Sign in with your license key to see the releases entitled to your organisation.
We approve your account against your support agreement and issue a license key bound to your channel entitlement.
Use the genesis CLI on your gap-host to authenticate, list channels, and pull signed Zarf artifacts.
Verify cosign signatures, ingest the Zarf bundles, and the operator reconciles your install. Nothing calls home.
Every bundle ships with a .cosign.bundle sidecar. Keyless OIDC-federated identity verifies build provenance.
CycloneDX SBOM beside every bundle — full container, OS, and Python dependency tree, ready for your vulnerability scanner.
A signed PDF attestation enumerates every change since the last release, including any HIPAA-relevant safeguards.