<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n" -->

---
title: Sigstore: Secure and Scalable Infrastructure for Signing...
description: Sigstore is an open-source project that aims to make software signing easy and readily available for people to use. It integrates with existing key management...
canonical: https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software | daily.dev
og:description: Sigstore is an open-source project that aims to make software signing easy and readily available for people to use. It integrates with existing key management...
og:url: https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n
og:image: https://api.daily.dev/og/posts/pfg2wcN2N.png
og:image:alt: Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software

**[InfoQ](https://daily.dev/sources/infoq)** · 26 min read · 0 upvotes · 0 comments

## Summary

Sigstore is an open-source project that aims to make software signing easy and readily available for people to use. It integrates with existing key management solutions and introduces the concept of keyless signing, focusing on identities rather than individual keys. Sigstore is widely supported in open-source software but not widely used. It offers improvements in key management, compromise detection, revocation, and identity verification. Many organizations, including Kubernetes, npm, and CPython, are already using Sigstore.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoq.com/presentations/scalable-infrastructure-sigstore/>

---

Tags: [#open-source](https://daily.dev/tags/open-source), [#devops](https://daily.dev/tags/devops), [#architecture](https://daily.dev/tags/architecture), [#supply-chain](https://daily.dev/tags/supply-chain), [#qcon](https://daily.dev/tags/qcon)

[View this post on daily.dev](https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software","url":"https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n"},"datePublished":"2024-02-29T09:33:04.875Z","dateModified":"2024-05-09T09:21:59.549Z","description":"Sigstore is an open-source project that aims to make software signing easy and readily available for people to use. It integrates with existing key management...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f6f2398502e06c6ba21447774e92b91a?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f6f2398502e06c6ba21447774e92b91a?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"InfoQ","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoQ","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/afc3bced3e1e4b188dd9127017a60e0c","url":"https://daily.dev/sources/infoq"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/sigstore-secure-and-scalable-infrastructure-for-signing-and-verifying-software-pfg2wcn2n","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"open-source,devops,architecture,supply-chain,qcon","timeRequired":"PT26M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoQ","item":"https://daily.dev/sources/infoq"},{"@type":"ListItem","position":3,"name":"Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software"}]}
```

