<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Octo-Sts on</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/tags/octo-sts/</link><description>Recent content in Octo-Sts on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Fri, 02 Oct 2026 13:51:55 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/tags/octo-sts/index.xml" rel="self" type="application/rss+xml"/><item><title>Set up and use Octo STS</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/open-source/octo-sts/set-up-octo-sts/</link><pubDate>Fri, 02 Oct 2026 13:51:55 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/open-source/octo-sts/set-up-octo-sts/</guid><description>&lt;p&gt;Octo STS is a GitHub App that exchanges OIDC tokens from your workloads for short-lived GitHub tokens, so your automation doesn&amp;rsquo;t need personal access tokens (PATs). This page shows you how to install Octo STS, write trust policies, exchange tokens, and fix failed exchanges. For background on why Octo STS exists, read &lt;a href="https://www.chainguard.dev/supply-chain-security-101/octo-sts-overview"&gt;Octo STS: Short-lived GitHub tokens without PATs&lt;/a&gt; in Supply Chain Security 101.&lt;/p&gt;
&lt;h2 id="how-the-token-exchange-works" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;How the token exchange works&lt;/span&gt;
&lt;a href="#how-the-token-exchange-works" class="anchor" aria-label="Link to How the token exchange works" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Octo STS issues tokens according to trust policies that you keep in your repositories:&lt;/p&gt;</description></item><item><title>Updating container images with Renovate (and no PATs!)</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/open-source/octo-sts/updating-container-images-with-renovate/</link><pubDate>Tue, 23 Dec 2025 09:30:00 +0100</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/open-source/octo-sts/updating-container-images-with-renovate/</guid><description>&lt;p&gt;In this video, Developer Relations Engineer Adrian Mouat shows you how you can update container images using Renovate with Octo STS, eliminating the need for GitHub Personal Access Tokens.&lt;/p&gt;
&lt;h2 id="video" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Video&lt;/span&gt;
&lt;a href="#video" class="anchor" aria-label="Link to Video" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/I0hWRMtdUyI?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="what-youll-learn" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What you&amp;rsquo;ll learn&lt;/span&gt;
&lt;a href="#what-youll-learn" class="anchor" aria-label="Link to What you&amp;rsquo;ll learn" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;How to set up Renovate as a GitHub Action&lt;/li&gt;
&lt;li&gt;Using Octo STS to eliminate Personal Access Tokens&lt;/li&gt;
&lt;li&gt;Configuring trust policies for automated workflows&lt;/li&gt;
&lt;li&gt;Setting up assumable identities for private registries&lt;/li&gt;
&lt;li&gt;Automating container image and GitHub Actions updates&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="transcript" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Transcript&lt;/span&gt;
&lt;a href="#transcript" class="anchor" aria-label="Link to Transcript" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;In this video, I&amp;rsquo;m going to show you how you can use Renovate to update container images and GitHub actions. At Chainguard, we do talk a lot about the need to keep software up to date. And in my opinion, it&amp;rsquo;s essential you do that for both security and maintainability. So, if you stay on an old version of a package for too long, there&amp;rsquo;s a strong chance that you&amp;rsquo;ll be bitten by an unpatched vulnerability. But also, the longer you stay on an old version, the harder updating becomes. So, it&amp;rsquo;s much better to do frequent small updates than it is to occasionally be forced into having to do major breaking updates.&lt;/p&gt;</description></item></channel></rss>