{
    "apiVersion": "v1",
    "items": [
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"all\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Include every rule in the default policy source. For experiments only. This is not expected to pass for Konflux builds without excluding some rules. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Everything (experimental)\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"*\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-27T18:14:38Z",
                "generation": 1,
                "name": "all",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4201",
                "uid": "c7b43a13-19e6-4551-a643-d2c0007df415"
            },
            "spec": {
                "description": "Include every rule in the default policy source. For experiments only. This is not expected to pass for Konflux builds without excluding some rules. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Everything (experimental)",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "*"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"default\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes rules for levels 1, 2 \\u0026 3 of SLSA v0.1. This is the default config used for new Konflux applications. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Default\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@slsa3\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-27T18:14:39Z",
                "generation": 1,
                "name": "default",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4202",
                "uid": "60285452-7900-426a-b9bd-8cc8a6ad3146"
            },
            "spec": {
                "description": "Includes rules for levels 1, 2 \u0026 3 of SLSA v0.1. This is the default config used for new Konflux applications. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Default",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@slsa3"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes the full set of rules and policies required internally by Red Hat when building Red Hat products. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Red Hat\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@redhat\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-27T18:14:39Z",
                "generation": 1,
                "name": "redhat",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4203",
                "uid": "fafa3082-f650-4d89-ad10-98b389491ef7"
            },
            "spec": {
                "description": "Includes the full set of rules and policies required internally by Red Hat when building Red Hat products. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Red Hat",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@redhat"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat-no-hermetic\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes most of the rules and policies required internally by Red Hat when building Red Hat products. It excludes the requirement of hermetic builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Red Hat (non hermetic)\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[\"hermetic_build_task\",\"tasks.required_tasks_found:prefetch-dependencies\"],\"include\":[\"@redhat\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-27T18:14:39Z",
                "generation": 1,
                "name": "redhat-no-hermetic",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4206",
                "uid": "969b57d7-286b-4cc2-8f8e-6dd6e4dc108c"
            },
            "spec": {
                "description": "Includes most of the rules and policies required internally by Red Hat when building Red Hat products. It excludes the requirement of hermetic builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Red Hat (non hermetic)",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [
                                "hermetic_build_task",
                                "tasks.required_tasks_found:prefetch-dependencies"
                            ],
                            "include": [
                                "@redhat"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat-trusted-tasks\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Rules used to verify Tekton Task definitions comply to Red Hat's standards.\",\"name\":\"Red Hat Trusted Tasks\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"kind\"]},\"data\":[\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/task-policy:konflux@sha256:bcd7394c39e87fe0934f92d3260df39739a2890ac90393b459de04549d1a3161\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-27T18:14:39Z",
                "generation": 1,
                "name": "redhat-trusted-tasks",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4207",
                "uid": "644af3b9-a120-4d54-b338-20f68d62d9a0"
            },
            "spec": {
                "description": "Rules used to verify Tekton Task definitions comply to Red Hat's standards.",
                "name": "Red Hat Trusted Tasks",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "kind"
                            ]
                        },
                        "data": [
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/task-policy:konflux@sha256:bcd7394c39e87fe0934f92d3260df39739a2890ac90393b459de04549d1a3161"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"slsa3\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Rules specifically related to levels 1, 2 \\u0026 3 of SLSA v0.1, plus a set of basic checks that are expected to pass for all Konflux builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"SLSA3\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@minimal\",\"@slsa3\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-27T18:14:39Z",
                "generation": 1,
                "name": "slsa3",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4208",
                "uid": "860153fd-8dd9-42c1-9b7d-2f6c8d67f60d"
            },
            "spec": {
                "description": "Rules specifically related to levels 1, 2 \u0026 3 of SLSA v0.1, plus a set of basic checks that are expected to pass for all Konflux builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "SLSA3",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@minimal",
                                "@slsa3"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:63c08a0d6c5646f5b4654fba89b9f73248f5033712e718c90a3e803b67d0a293",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        }
    ],
    "kind": "List",
    "metadata": {
        "resourceVersion": ""
    }
}
