{
    "apiVersion": "v1",
    "items": [
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"all\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Include every rule in the default policy source. For experiments only. This is not expected to pass for Konflux builds without excluding some rules. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Everything (experimental)\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"*\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=671e5c26f93de6a0931f49e2e2d7f0eb4d5df6c8\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-20T21:21:23Z",
                "generation": 1,
                "name": "all",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4124",
                "uid": "9a035e1a-e128-4078-a06a-75fd208892db"
            },
            "spec": {
                "description": "Include every rule in the default policy source. For experiments only. This is not expected to pass for Konflux builds without excluding some rules. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Everything (experimental)",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "*"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=671e5c26f93de6a0931f49e2e2d7f0eb4d5df6c8"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"default\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes rules for levels 1, 2 \\u0026 3 of SLSA v0.1. This is the default config used for new Konflux applications. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Default\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@slsa3\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-20T21:21:23Z",
                "generation": 1,
                "name": "default",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4125",
                "uid": "ddb45dc6-932c-4f92-835d-030428393319"
            },
            "spec": {
                "description": "Includes rules for levels 1, 2 \u0026 3 of SLSA v0.1. This is the default config used for new Konflux applications. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Default",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@slsa3"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes the full set of rules and policies required internally by Red Hat when building Red Hat products. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Red Hat\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@redhat\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:d0e34b6ed08e9e6922134693f7ca8130e04849b82318150c4b4b2f721b8a4bfb\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-20T21:21:23Z",
                "generation": 1,
                "name": "redhat",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4126",
                "uid": "44057d8b-f565-4043-a077-ba6e7b1164eb"
            },
            "spec": {
                "description": "Includes the full set of rules and policies required internally by Red Hat when building Red Hat products. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Red Hat",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@redhat"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:d0e34b6ed08e9e6922134693f7ca8130e04849b82318150c4b4b2f721b8a4bfb",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat-no-hermetic\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes most of the rules and policies required internally by Red Hat when building Red Hat products. It excludes the requirement of hermetic builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Red Hat (non hermetic)\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[\"hermetic_build_task\",\"tasks.required_tasks_found:prefetch-dependencies\"],\"include\":[\"@redhat\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=671e5c26f93de6a0931f49e2e2d7f0eb4d5df6c8\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-20T21:21:23Z",
                "generation": 1,
                "name": "redhat-no-hermetic",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4127",
                "uid": "1d908c33-32cd-4f0b-bb07-cbb41663a85d"
            },
            "spec": {
                "description": "Includes most of the rules and policies required internally by Red Hat when building Red Hat products. It excludes the requirement of hermetic builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Red Hat (non hermetic)",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [
                                "hermetic_build_task",
                                "tasks.required_tasks_found:prefetch-dependencies"
                            ],
                            "include": [
                                "@redhat"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=671e5c26f93de6a0931f49e2e2d7f0eb4d5df6c8"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat-trusted-tasks\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Rules used to verify Tekton Task definitions comply to Red Hat's standards.\",\"name\":\"Red Hat Trusted Tasks\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"kind\"]},\"data\":[\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/task-policy:konflux@sha256:fb2c1cfc0b68f6aca13eb9c63ae90bbabbc5384818484d8358f66cd9b53d82c9\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-20T21:21:24Z",
                "generation": 1,
                "name": "redhat-trusted-tasks",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4129",
                "uid": "535dfeaa-5a1f-452d-8ad1-6664580ccdac"
            },
            "spec": {
                "description": "Rules used to verify Tekton Task definitions comply to Red Hat's standards.",
                "name": "Red Hat Trusted Tasks",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "kind"
                            ]
                        },
                        "data": [
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/task-policy:konflux@sha256:fb2c1cfc0b68f6aca13eb9c63ae90bbabbc5384818484d8358f66cd9b53d82c9"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"slsa3\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Rules specifically related to levels 1, 2 \\u0026 3 of SLSA v0.1, plus a set of basic checks that are expected to pass for all Konflux builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"SLSA3\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@minimal\",\"@slsa3\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-20T21:21:24Z",
                "generation": 1,
                "name": "slsa3",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4130",
                "uid": "39c8b953-87df-4518-bb54-520d2af28ec7"
            },
            "spec": {
                "description": "Rules specifically related to levels 1, 2 \u0026 3 of SLSA v0.1, plus a set of basic checks that are expected to pass for all Konflux builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "SLSA3",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@minimal",
                                "@slsa3"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:cc03b2c00a336b9b264fbb5a077150a0a27549be75fa3ba4fb5c1aa1e826bc3c",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:be53571e210f76978fb3d89233aa9740cde4e3c66707db029728a81479ad3f73"
                        ]
                    }
                ]
            }
        }
    ],
    "kind": "List",
    "metadata": {
        "resourceVersion": ""
    }
}
