Sigstore is an open-source project that aims to make software signing easy and readily available for people to use. It integrates with existing key management solutions and introduces the concept of keyless signing, focusing on identities rather than individual keys. Sigstore is widely supported in open-source software but not

26m read time From infoq.com
Post cover image
Table of contents
TranscriptWhy Software Signing?Software Signing TodayChallenges with Traditional SigningSigstore (Goals)Sigstore - Keyless SigningDemoKubernetes Admission ControllersChallenges with Traditional Signing (Recap)Why Do We Trust Sigstore?The Role of Identity ProvidersCase Study - Verifying ImagesCase Study - npmWhat You Should DoQuestions and Answers

Sort: