{
    "apiVersion": "v1",
    "items": [
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"all\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Include every rule in the default policy source. For experiments only. This is not expected to pass for Konflux builds without excluding some rules. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Everything (experimental)\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"*\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-24T14:56:39Z",
                "generation": 1,
                "name": "all",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4113",
                "uid": "32257306-7083-4502-9d68-b2fd32835b76"
            },
            "spec": {
                "description": "Include every rule in the default policy source. For experiments only. This is not expected to pass for Konflux builds without excluding some rules. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Everything (experimental)",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "*"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"default\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes rules for levels 1, 2 \\u0026 3 of SLSA v0.1. This is the default config used for new Konflux applications. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Default\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@slsa3\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-24T14:56:39Z",
                "generation": 1,
                "name": "default",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4124",
                "uid": "726a783a-0502-48af-ae44-11118f5da288"
            },
            "spec": {
                "description": "Includes rules for levels 1, 2 \u0026 3 of SLSA v0.1. This is the default config used for new Konflux applications. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Default",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@slsa3"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes the full set of rules and policies required internally by Red Hat when building Red Hat products. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Red Hat\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@redhat\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-24T14:56:39Z",
                "generation": 1,
                "name": "redhat",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4126",
                "uid": "cfc9f640-1f0d-4945-8874-f2a9af205ad9"
            },
            "spec": {
                "description": "Includes the full set of rules and policies required internally by Red Hat when building Red Hat products. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Red Hat",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@redhat"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat-no-hermetic\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Includes most of the rules and policies required internally by Red Hat when building Red Hat products. It excludes the requirement of hermetic builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"Red Hat (non hermetic)\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[\"hermetic_build_task\",\"tasks.required_tasks_found:prefetch-dependencies\"],\"include\":[\"@redhat\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-24T14:56:40Z",
                "generation": 1,
                "name": "redhat-no-hermetic",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4129",
                "uid": "b88d7131-3ac9-4a72-a051-ee0db7204d51"
            },
            "spec": {
                "description": "Includes most of the rules and policies required internally by Red Hat when building Red Hat products. It excludes the requirement of hermetic builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "Red Hat (non hermetic)",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [
                                "hermetic_build_task",
                                "tasks.required_tasks_found:prefetch-dependencies"
                            ],
                            "include": [
                                "@redhat"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"redhat-trusted-tasks\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Rules used to verify Tekton Task definitions comply to Red Hat's standards.\",\"name\":\"Red Hat Trusted Tasks\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"kind\"]},\"data\":[\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/task-policy:konflux@sha256:d653a9e8c2280556561dfea239190f56e6d4b34a0a2ae7fda58fd2221abaeb77\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-24T14:56:40Z",
                "generation": 1,
                "name": "redhat-trusted-tasks",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4131",
                "uid": "8198ea09-0817-438a-abde-23435417c5b7"
            },
            "spec": {
                "description": "Rules used to verify Tekton Task definitions comply to Red Hat's standards.",
                "name": "Red Hat Trusted Tasks",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "kind"
                            ]
                        },
                        "data": [
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/task-policy:konflux@sha256:d653a9e8c2280556561dfea239190f56e6d4b34a0a2ae7fda58fd2221abaeb77"
                        ]
                    }
                ]
            }
        },
        {
            "apiVersion": "appstudio.redhat.com/v1alpha1",
            "kind": "EnterpriseContractPolicy",
            "metadata": {
                "annotations": {
                    "kubectl.kubernetes.io/last-applied-configuration": "{\"apiVersion\":\"appstudio.redhat.com/v1alpha1\",\"kind\":\"EnterpriseContractPolicy\",\"metadata\":{\"annotations\":{},\"name\":\"slsa3\",\"namespace\":\"enterprise-contract-service\"},\"spec\":{\"description\":\"Rules specifically related to levels 1, 2 \\u0026 3 of SLSA v0.1, plus a set of basic checks that are expected to pass for all Konflux builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.\",\"name\":\"SLSA3\",\"publicKey\":\"k8s://openshift-pipelines/public-key\",\"sources\":[{\"config\":{\"exclude\":[],\"include\":[\"@minimal\",\"@slsa3\"]},\"data\":[\"oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9\",\"github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec\"],\"name\":\"Default\",\"policy\":[\"oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae\"]}]}}\n"
                },
                "creationTimestamp": "2026-03-24T14:56:40Z",
                "generation": 1,
                "name": "slsa3",
                "namespace": "enterprise-contract-service",
                "resourceVersion": "4134",
                "uid": "b48c422c-ce41-49f4-a9e3-e06f86ba7530"
            },
            "spec": {
                "description": "Rules specifically related to levels 1, 2 \u0026 3 of SLSA v0.1, plus a set of basic checks that are expected to pass for all Konflux builds. Available collections are defined in https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/release_policy.html#_available_rule_collections. If a different policy configuration is desired, this resource can serve as a starting point. See the docs on how to include and exclude rules https://redhat-appstudio.github.io/docs.stonesoup.io/ec-policies/policy_configuration.html#_including_and_excluding_rules.",
                "name": "SLSA3",
                "publicKey": "k8s://openshift-pipelines/public-key",
                "sources": [
                    {
                        "config": {
                            "exclude": [],
                            "include": [
                                "@minimal",
                                "@slsa3"
                            ]
                        },
                        "data": [
                            "oci::quay.io/konflux-ci/tekton-catalog/data-acceptable-bundles:latest@sha256:8b265f492939b1174a48b3499a50a691021e7e20e6063444fb369aeed66ce7b9",
                            "github.com/release-engineering/rhtap-ec-policy.git//data?ref=dd1a3dd1bf2299e1da9936b89e7279b6ab443bec"
                        ],
                        "name": "Default",
                        "policy": [
                            "oci::quay.io/conforma/release-policy:konflux@sha256:6eb386faaf76de0d7dbc9f9e770a7f5639ebcee88e4ed4f004f8053189b21eae"
                        ]
                    }
                ]
            }
        }
    ],
    "kind": "List",
    "metadata": {
        "resourceVersion": ""
    }
}
