InfoQ
Read post

Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software

Sigstore is an open-source project that aims to make software signing easy and readily available for people to use. It integrates with existing key management solutions and introduces the concept of keyless signing, focusing on identities rather than individual keys. Sigstore is widely supported in open-source software but not widely used. It offers improvements in key management, compromise detection, revocation, and identity verification. Many organizations, including Kubernetes, npm, and CPython, are already using Sigstore.

    #open-source#devops#architecture#supply-chain#qcon
Feb 29, 2024•26m read time•From infoq.com
Post cover image
Table of contents
TranscriptWhy Software Signing?Software Signing TodayChallenges with Traditional SigningSigstore (Goals)Sigstore - Keyless SigningDemoKubernetes Admission ControllersChallenges with Traditional Signing (Recap)Why Do We Trust Sigstore?The Role of Identity ProvidersCase Study - Verifying ImagesCase Study - npmWhat You Should DoQuestions and Answers
15 Impressions
InfoQ's image
InfoQ

InfoQ is a leading online platform for software developers, architects, and technical leaders, provi...

1.4K Followers

•

6.2K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard