Unsigned initContainer rejected SELECTED VISIBLE OUTPUT — not a full log Selected visible output: TEST 1 - Mixed trusted + untrusted containers resource Pod/default/test-mixed-containers was blocked verify-image-signature: supply-chain-demo:unsigned-test: no signatures found verify-provenance-attestation: no matching attestations verify-sbom-attestation: no matching attestations RESULT 1: PASS - mixed-container bypass DENIED TEST 2 - Unsigned initContainer resource Pod/default/test-init-unsigned was blocked verify-image-signature: supply-chain-demo:unsigned-test: no signatures found RESULT 2: PASS - unsigned initContainer DENIED Original: https://github.com/devSatym/gcp-supply-chain-security/blob/cbbc807c0c150e106affa89fbb1b9e8349005749/docs/my-validation/11-init-bypass-blocked.png Limitations: - The baseline YAML shows both fixtures use an unsigned initContainer alongside a signed regular container. - This does not establish unsigned regular sidecar or ephemeral-container subresource coverage. - The capture's final broad phrase about protected bypass paths is narrowed to the fields actually tested.