<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sigstore Community Blog</title><link>https://lukehinds.github.io/sigstore-blog/</link><description>Recent content on Sigstore Community Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 10 Oct 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://lukehinds.github.io/sigstore-blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Rekor v2 GA - Cheaper to run, simpler to maintain</title><link>https://lukehinds.github.io/sigstore-blog/rekor-v2-ga/</link><pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/rekor-v2-ga/</guid><description>We are very excited to announce the General Availability of Rekor v2!
Rekor v2 is a redesigned and modernized Rekor, Sigstore&amp;rsquo;s signature transparency log, transitioning its backend to a tile-backed transparency log implementation to simplify maintenance and lower operational costs. Learn more about Rekor v2 in our previous blog post announcing Alpha.
We have added support for Rekor v2 upload and verification to Cosign v2.6.0, along with the Go, Python, and Java clients.</description></item><item><title>Cosign v3 is now available</title><link>https://lukehinds.github.io/sigstore-blog/cosign-3-0-available/</link><pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-3-0-available/</guid><description>The past few years have been incredible in the Sigstore ecosystem, seeing Sigstore-signed in-toto attestations be adopted by Homebrew (May 2024), PyPI (November 2024), Maven Central (January 2025), model signing in NVIDIA&amp;rsquo;s NGC (July 2025), and several others.
These deployments make use of great Sigstore features, like the ability to verify content offline, being able to fetch new verification key material with The Update Framework, and the ability to use a tile-based transparency log that&amp;rsquo;s much easier to operate and scale.</description></item><item><title>Announcing the Sigstore Transparency Log Research Dataset</title><link>https://lukehinds.github.io/sigstore-blog/rekor-bigquery-dataset/</link><pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/rekor-bigquery-dataset/</guid><description>We&amp;rsquo;re pleased to announce the creation of a new BigQuery public dataset, rekor. The rekor dataset is an easily-queryable mirror of the public good instance of Sigstore&amp;rsquo;s transparency log, Rekor.
As a reminder, signing events are recorded in Rekor, Sigstore&amp;rsquo;s append-only transparency log. Software consumers rely on cryptographic proofs of log inclusion to verify that software artifacts are recorded to the log. Software producers can verify metadata in the log, verifying that the recorded signature metadata was produced as expected when their identities or keys were used to sign artifacts, using a Rekor monitor.</description></item><item><title>Trusting AI Models in Kubernetes: Introducing the Sigstore Model Validation Operator</title><link>https://lukehinds.github.io/sigstore-blog/model-validation-operator-v1.0.1/</link><pubDate>Mon, 23 Jun 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/model-validation-operator-v1.0.1/</guid><description>As machine learning becomes deeply embedded in critical infrastructure, the question of trust in deployed models is increasingly critical. How can we be sure that an AI model running in a Kubernetes cluster is exactly what it claims to be?
The OpenSSF AI/ML working group believes the answer can be found in signing AI models. A long-standing practice in traditional software distribution is to leverage cryptographic signatures to help end-users verify provenance: that software is authentic, has not been tampered with, and was authored by the expected creator.</description></item><item><title>Sigstore &amp; Post-Quantum Cryptography (2025)</title><link>https://lukehinds.github.io/sigstore-blog/post-quantum-2025/</link><pubDate>Fri, 06 Jun 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/post-quantum-2025/</guid><description>In the coming years, systems will transition to post-quantum cryptographic algorithms (PQCA). There is some inherent tension in these transitions as we learn things through adoption, but making decisions too soon can saddle you with tech debt. The quick summary is that the Sigstore project wants to enable people to sign content with PQCA keys as soon as possible, and adopt PQCA in the Sigstore services (like Fulcio, Rekor, and a timestamp authority) when reliable and vetted PQCA is available in the Go ecosystem.</description></item><item><title>sigstore-go 1.0 is now available</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-go-1-0-now-available/</link><pubDate>Mon, 12 May 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-go-1-0-now-available/</guid><description>We love Go within the Sigstore community, and it&amp;rsquo;s been our language of choice since we got started. Cosign, Rekor, Fulcio, Policy Controller, and Timestamp Authority are all written in Go, and we&amp;rsquo;re lucky to have such a vibrant community of Go developers.
Cosign was the de-facto Sigstore &amp;ldquo;client&amp;rdquo; from the beginning. Originally designed as a container image signing tool, it has become much more, introducing signing with ephemeral keys (with Fulcio), blob signing, attestation support, multi-cloud KMS support, and many more features.</description></item><item><title>Verifying Sigstore Bundles as an End User</title><link>https://lukehinds.github.io/sigstore-blog/cosign-verify-end-user/</link><pubDate>Fri, 02 May 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-verify-end-user/</guid><description>There&amp;rsquo;s a mnemonic for quickly determining if a bicycle is safe to ride: &amp;ldquo;ABC&amp;rdquo; for checking the air in the tires, ensuring the brakes are functional, and checking the chain. It doesn&amp;rsquo;t definitively answer the question &amp;ldquo;is this bike safe?&amp;rdquo; but it does give you a quick starting point for your assessment.
Let&amp;rsquo;s say you download some software and it comes with a Sigstore bundle. Similarly, there isn&amp;rsquo;t a quick, definitive answer to &amp;ldquo;is this software safe to use?</description></item><item><title>Rekor v2 - Cheaper to run, simpler to maintain</title><link>https://lukehinds.github.io/sigstore-blog/rekor-v2-alpha/</link><pubDate>Thu, 17 Apr 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/rekor-v2-alpha/</guid><description>We are very excited to announce the alpha release of Rekor v2!
Rekor v2 is a redesigned and modernized Rekor, Sigstore&amp;rsquo;s signature transparency log, transitioning its backend to a modern, tile-backed transparency log implementation to simplify maintenance and lower operational costs.
Major changes include:
A new storage backend, replacing Trillian with Trillian-Tessera. Tile-based logs are cheaper to run and easier to deploy, maintain and scale. To learn more about the benefits of tile-based logs, read this blog post A redesigned and simplified API, using the learnings from operating public-good Rekor over the past 2 years Stronger security guarantees that the log remains append-only by integrating witnessing directly into Rekor (To be implemented) For the initial release, we are providing a binary and container for developers.</description></item><item><title>KMS Plugins for Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/kms-plugins/</link><pubDate>Mon, 07 Apr 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/kms-plugins/</guid><description>Cosign and private deployments of Fulcio and Rekor can use a KMS-managed key for signing artifacts. We currently have built-in support for AWS, Azure, Google Cloud Platform, and Hashicorp Vault KMSs. This has been a challenge for customers that require alternative or custom KMS solutions.
To enable such use-cases, we have implemented a new plugin system for alternate KMS providers. Organizations can independently and privately develop &amp;amp; distribute their plugins without needing downstream updates to libraries to support additional KMS providers as build-time dependencies.</description></item><item><title>Taming the Wild West of ML: Practical Model Signing with Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/model-transparency-v1.0/</link><pubDate>Fri, 04 Apr 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/model-transparency-v1.0/</guid><description>Over the past year, in collaboration with OpenSSF, NVIDIA and HiddenLayer, we have worked on bringing Sigstore signatures to the world of machine learning, making ML models tamper resistant via transparent signatures. Today we are pleased to announce the launch of version 1.0 of the model-signing project, built on top of sigstore-python. After installing via pip install model-signing, users can use the CLI to sign and verify models, as per the following examples:</description></item><item><title>New Terraform Modules Repository</title><link>https://lukehinds.github.io/sigstore-blog/terraform-modules/</link><pubDate>Wed, 05 Mar 2025 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/terraform-modules/</guid><description>New Terraform Modules Repository The Terraform modules for running a private deployment of Sigstore have been moved to a dedicated repository, terraform-modules.
We currently support Google Cloud Platform as a cloud provider. We welcome any community contributions for other cloud providers.
Deprecation for Terraform Modules under Scaffolding Effectively immediately, the Terraform modules in the scaffolding repository will no longer be updated. If you are relying on Terraform for your private deployment, please update references for scaffolding to the new terraform-modules repository.</description></item><item><title>Using rekor-monitor to Scan Your Transparency Logs</title><link>https://lukehinds.github.io/sigstore-blog/using-rekor-monitor/</link><pubDate>Thu, 21 Nov 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/using-rekor-monitor/</guid><description>Overview As part of the tool suite within Sigstore that focuses on providing transparency in the software supply chain, Rekor, Sigstore&amp;rsquo;s signature transparency log, and Fulcio&amp;rsquo;s certificate transparency log provides discoverability and auditability for signed artifact metadata and code-signing certificates. These immutable read-only logs help secure the software supply chain by making it easier to show what actions have been performed by a compromised identity.
A variety of different improvements have recently been integrated into rekor-monitor to make it easier to use.</description></item><item><title>PyPI's Sigstore-powered attestations are now generally available</title><link>https://lukehinds.github.io/sigstore-blog/pypi-attestations-ga/</link><pubDate>Thu, 14 Nov 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/pypi-attestations-ga/</guid><description>Check out the PyPI blog and Trail of Bits blog for more user-facing and technical details, respectively!
Over the past year, the Google Open Source Security Team and Trail of Bits have worked together to implement PEP 740, a Python packaging standard that allows users to upload Sigstore-based attestations to the Python Package Index.
Today we&amp;rsquo;re pleased to announce that attestation support on PyPI is generally available, meaning that project maintainers can submit attestations for both PyPI and downstream users to verify.</description></item><item><title>Fulcio Streamlines Onboarding for CI Identity Providers</title><link>https://lukehinds.github.io/sigstore-blog/fulcio-ci-provider/</link><pubDate>Thu, 05 Sep 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/fulcio-ci-provider/</guid><description>TL;DR Fulcio, the Sigstore certificate authority, has introduced a new feature that simplifies the onboarding process for identity providers, mainly for continuous integration. This enhancement eliminates the need for complex, provider-specific logic implementations.
Traditionally, integrating a new identity provider for CI involved significant development effort, which required understanding the codebase and cutting a new release. However, with this update, onboarding is reduced to configuring a YAML file which houses essential provider information for building certificate extensions based on ID token claims.</description></item><item><title>Announcing sigstore-java 1.0</title><link>https://lukehinds.github.io/sigstore-blog/announcing-sigstore-java-1-0/</link><pubDate>Wed, 28 Aug 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/announcing-sigstore-java-1-0/</guid><description>sigstore-java The sigstore-java project brings the Sigstore signing and verification paradigm to the Java ecosystem. It is built natively in Java and is easy to integrate with your Maven and Gradle builds or custom workflows.
1.0 Stable Release Today, thanks to the support of the community and work of our contributors, we’re excited to announce a 1.0 stable release of the sigstore-java client. This includes a library(dev.sigstore:sigstore-java) for programmatic access to the sigstore signing and verification APIs.</description></item><item><title>cosign Verification of npm Provenance, GitHub Artifact Attestations, and Homebrew Provenance</title><link>https://lukehinds.github.io/sigstore-blog/cosign-verify-bundles/</link><pubDate>Tue, 27 Aug 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-verify-bundles/</guid><description>One of the features of the cosign v2.4.0 release allows you to verify attestations in the bundle format used by npm provenance, GitHub Artifact Attestations, and Homebrew provenance.
This is part of all Sigstore clients supporting the bundle format as outlined in the community roadmap.
We&amp;rsquo;ll show how to perform that verification for each ecosystem, and explain some of the details involved. You&amp;rsquo;ll notice these examples follow the same general pattern of getting an artifact to verify, getting the bundle that contains the signed attestation about that artifact, and then providing a verification policy to cosign via command line flags.</description></item><item><title>Announcing SigstoreCon: Supply Chain Day</title><link>https://lukehinds.github.io/sigstore-blog/sigstorecon-supply-chain-day/</link><pubDate>Wed, 14 Aug 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstorecon-supply-chain-day/</guid><description>Announcing SigstoreCon: Supply Chain Day! Join us for SigstoreCon: Supply Chain Day! Co-located with Kubecon NA 2024 in Salt Lake City, attendees will learn about simplifying signing and verification for digital artifacts using Sigstore, as well as related software supply chain efforts such as SLSA, The Update Framework, binary transparency, and more! CFP deadline is September 13.
Learn more and register for SigstoreCon here!
Topics for Talks We are inviting submissions for Session Presentations (30 min) and Lightning Talks (10 min).</description></item><item><title>sigstore-go verification and signing now in beta</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-go-signing-beta/</link><pubDate>Wed, 26 Jun 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-go-signing-beta/</guid><description>sigstore-go verification and signing now in beta Recent sigstore-go releases include signing support, as well moving both the verification and signing API from unstable to beta.
sigstore-go is used in several open source projects like the SLSA verifier, the GitHub CLI, and Stacklok Minder.
Cosign and sigstore-go are similar in that they are both written in Go, but the main differences are that sigstore-go is not a full-fledged CLI, and that it supports the protobuf bundle format.</description></item><item><title>Homebrew's Sigstore-powered provenance is in beta</title><link>https://lukehinds.github.io/sigstore-blog/homebrew-build-provenance/</link><pubDate>Tue, 14 May 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/homebrew-build-provenance/</guid><description>Last November, Alpha-Omega and Trail of Bits announced a collaboration to bring build provenance to homebrew-core.
Today, we are pleased to announce that the core of that work is live and in public beta: homebrew-core is now using Sigstore to cryptographically attest to all bottles built in the official Homebrew CI.
This is aligned with Sigstore&amp;rsquo;s mission: to support frictionless and transparent provenance on all artifact registries.
Homebrew&amp;rsquo;s build provenance follows last year&amp;rsquo;s npm provenance feature, making Homebrew the second major packaging ecosystem to adopt Sigstore!</description></item><item><title>Sigstore - An OpenSSF Graduated Project</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-openssf-graduation/</link><pubDate>Thu, 14 Mar 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-openssf-graduation/</guid><description>Sigstore Graduates: A Monumental Step Towards Secure Software Supply chain security took a giant leap forward this month as Sigstore officially became a graduated project within the Open Source Security Foundation (OpenSSF). This milestone is a testament to Sigstore&amp;rsquo;s maturity, adoption, and its undeniable impact on making the creation and distribution of software more trustworthy.
What is Sigstore? For those unfamiliar, Sigstore is a suite of tools designed to streamline secure software signing &amp;amp; verification of artifacts such as binaries, containers and attestations.</description></item><item><title>Sigstore Announcement: New TUF Trust Root and Client Compatibility</title><link>https://lukehinds.github.io/sigstore-blog/tuf-root-update/</link><pubDate>Thu, 14 Mar 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/tuf-root-update/</guid><description>New TUF Trust Root We are planning to publish a new TUF trust root for Sigstore. This update does not contain any functional changes, but it does update to the latest version of the TUF specification. This means that older clients may not be able to load it properly. The current compatibility is as follows:
Cosign Releases &amp;gt;= v2.2.0 (v2.2.0 released Aug 31st 2023) work. Older Cosign clients (&amp;lt; v2.2.0) will not work v1.</description></item><item><title>Sigstore February Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-feb24-roundup-2024/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-feb24-roundup-2024/</guid><description>Welcome to the February edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings.
Events KubeCon Europe 2024 The next KubeCon Europe will be held on 19th – 22nd March.
There are several Sigstore related talks and events planned for KubeCon Europe, including:
Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev &amp;amp; Yonghe Zhao, Yahoo Navigating the Software Supply Chain Defense Landscape - Marina Moore &amp;amp; Aditya Sirish A Yelgundhalli, New York University Contribfest: Enable Additional Signing Mechanisms for TUF and in-toto: No Cryptography Skills Required Open Source Summit North America 2024 The next Open Source Summit North America will be held on April 16th – 18th</description></item><item><title>Sigstore January Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-january-roundup-2024/</link><pubDate>Tue, 30 Jan 2024 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-january-roundup-2024/</guid><description>Welcome to the January edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings.
Events KubeCon Europe 2024 The next KubeCon Europe will be held on 19th – 22nd March.
There are serveral Sigstore related talks and events planned for KubeCon Europe, including:
Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev &amp;amp; Yonghe Zhao, Yahoo Navigating the Software Supply Chain Defense Landscape - Marina Moore &amp;amp; Aditya Sirish A Yelgundhalli, New York University Contribfest: Enable Additional Signing Mechanisms for TUF and in-toto: No Cryptography Skills Required FOSDEM 2024 The next FOSDEM will be held in Brussels, Belgium on the 3rd &amp;amp; 4th February 2024 along with a talk on Sigstore and SLSA by John Viega.</description></item><item><title>Sigstore November Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-november-roundup-2023/</link><pubDate>Thu, 30 Nov 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-november-roundup-2023/</guid><description>Welcome to the November edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings.
Sigstore Google Season of Docs 2023 Case Study A very comprehisive case study has been published on the Sigstore docs wiki about the Sigstore project&amp;rsquo;s participation in the 2023 program.
Thank you Lisa Tagliaferri for all your hard work on this and making it a success!
Latest Releases Rekor v1.</description></item><item><title>Announcing sigstore-go</title><link>https://lukehinds.github.io/sigstore-blog/announcing-sigstore-go/</link><pubDate>Thu, 05 Oct 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/announcing-sigstore-go/</guid><description>Announcing sigstore-go Today we’re excited to announce a new open source library, sigstore-go, that represents the future of Sigstore’s support for the Go programming language. Since the beginning, Sigstore has been primarily written in Go but there has been a gap over the past year or so since we established the Protobufs-based bundle format: the de facto standard client (Cosign) lacks support for it. Cosign-the-library is also heavily focused on OCI use cases, which makes it difficult for library integrators who want to limit their implementations to core sign/verify flows and it also supports a wide variety of verification options, which creates potentially confusing duplication.</description></item><item><title>OpenPubkey and Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/openpubkey-and-sigstore/</link><pubDate>Thu, 05 Oct 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/openpubkey-and-sigstore/</guid><description>Disclaimer: The following is representative of the authors views, and not necessarily that of the sigstore community.
OpenPubKey was announced October 4th by Docker and BastionZero as a new Linux Foundation project. It’s a new scheme for using OIDC providers to sign arbitrary objects. It bears a lot of resemblance to Sigstore, so I thought it would be worth taking some time to explain the differences, including some advantages and disadvantages.</description></item><item><title>npm's Sigstore-powered provenance goes GA</title><link>https://lukehinds.github.io/sigstore-blog/npm-provenance-ga/</link><pubDate>Tue, 03 Oct 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/npm-provenance-ga/</guid><description>Last week saw the GA release of npm CLI’s native Sigstore functionality, a project over a year in the making. This is a tremendous milestone for the adoption of Sigstore in open source projects and represents huge progress in effecting a cultural shift toward expecting provenance to exist for software components. It also helps move npm toward the best practices articulated by the OpenSSF&amp;rsquo;s Securing Open Source Repos Working Group in their document &amp;ldquo;Build Provenance for All Package Registries&amp;rdquo;.</description></item><item><title>Announcing sigstore-python 2.0</title><link>https://lukehinds.github.io/sigstore-blog/announcing-sigstore-python-20/</link><pubDate>Fri, 29 Sep 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/announcing-sigstore-python-20/</guid><description>We are delighted to announce the 2.0 release of sigstore-python, a Python client for signing and verifying Sigstore signatures!
$ python -m pip install -U sigstore $ python -m sigstore --version sigstore 2.0.0 This release has been in the works for a while, and contains a number of significant improvements and breaking changes to both the sigstore CLI and Python APIs.
We&amp;rsquo;ve also updated the official sigstore/gh-action-sigstore-python action to use the latest 2.</description></item><item><title>Trusted Time in Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/trusted-time/</link><pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/trusted-time/</guid><description>Time in Sigstore Time is a critical component of Sigstore. It&amp;rsquo;s used to verify that a short-lived certificate issued by Fulcio was valid at a previous point, when the artifact was signed.
As a reminder, the default signing flow for Sigstore clients includes the following:
Signer requests an identity token from an OpenID Connect provider Signer generates an ephemeral keypair Signer sends the public key and identity token to Fulcio, Sigstore&amp;rsquo;s certificate authority Fulcio issues a short-lived (10 minute expiration) code-signing certificate Signer signs the artifact, and uploads the artifact, the certificate, and signature to Rekor, Sigstore&amp;rsquo;s transparency log During artifact verification, a client must verify the certificate.</description></item><item><title>Sigstore Announcement: No Longer Publishing Cosign Releases to GCS Bucket</title><link>https://lukehinds.github.io/sigstore-blog/cosign-releases-bucket-deprecation/</link><pubDate>Mon, 31 Jul 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-releases-bucket-deprecation/</guid><description>We are announcing that we will stop publishing Cosign releases to the GCS bucket named cosign-releases. The current v2.1.1 release of Cosign is the last release that will be pushed to the bucket, and public access to the GCS bucket will be removed on October 31st, 2023.
Why are we deprecating the GCS bucket? We are deprecating the GCS bucket because we already use GitHub in the Sigstore community, and it is a reliable and secure platform for hosting release artifacts.</description></item><item><title>Announcing the Sigstore Clients Special Interest Group (sig-clients)</title><link>https://lukehinds.github.io/sigstore-blog/announcing-sig-clients/</link><pubDate>Fri, 26 May 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/announcing-sig-clients/</guid><description>We are delighted to announce the creation of the Clients Special Interest Group (sig-clients) for the Sigstore project. This exciting new initiative marks the first SIG for Sigstore and serves as an experiment in organizing efforts across the Sigstore project.
The sig-clients repository is your one-stop shop for all things related to Sigstore clients across various languages and ecosystems. This group has the following mission:
Make Sigstore clients across languages/ecosystems easy-to-write, compatible, and secure by providing shared designs/documentation, data formats, and test suites.</description></item><item><title>Bringing Privacy and Security Full Circle Through Automated Authentication</title><link>https://lukehinds.github.io/sigstore-blog/case-study-smallstep/</link><pubDate>Fri, 19 May 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/case-study-smallstep/</guid><description>This is a Sigstore case study contributed by Max Furman of Smallstep
No matter how well you think you secure your software supply chain, the possibility of a breach is always in the back of your mind. We recently had a moment of panic where we thought, “Did someone get access to some things we stored in secrets?” I wondered what damage they’d done and how quickly we could repair it.</description></item><item><title>Sigstore Support in npm launches for Public Beta</title><link>https://lukehinds.github.io/sigstore-blog/npm-public-beta/</link><pubDate>Wed, 19 Apr 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/npm-public-beta/</guid><description>We&amp;rsquo;re thrilled to announce that the npm project has launched a public beta, bundling Sigstore support directly into the npm Command-Line Interface (CLI). This innovation brings strong origin guarantees to the npm ecosystem and marks the first time that a large package registry technology is using public software signatures to attest to a package’s originating source code and build instructions.
Sigstore is an OpenSSF project that enables developers to validate that the software they are using is exactly what it claims to be using cryptographic digital signatures and transparency log technologies.</description></item><item><title>Cosign 2.0 Released!</title><link>https://lukehinds.github.io/sigstore-blog/cosign-2-0-released/</link><pubDate>Thu, 23 Feb 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-2-0-released/</guid><description>Cosign 2.0 has arrived! Cosign 2.0 follows Sigstore&amp;rsquo;s General Availability launch, which offers production grade stable services for artifact signing and verification.
Cosign&amp;rsquo;s most significant change is to no longer require COSIGN_EXPERIMENTAL=1, since the Sigstore services are now stable! By default, Cosign will fetch an identity-based certificate from Fulcio when a signing key is not provided, and upload the signature and signing key to Rekor to provide transparency.
The following is the list of breaking changes:</description></item><item><title>Cosign and Policy-controller with GKE, Artifact Registry and KMS</title><link>https://lukehinds.github.io/sigstore-blog/cosign-and-policy-controller-with-gke-artifact-registry-and-cloud-kms/</link><pubDate>Fri, 10 Feb 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-and-policy-controller-with-gke-artifact-registry-and-cloud-kms/</guid><description>As soon as I came back from KubeCon NA 2022, my first ever in-person KubeCon, I felt re-energized. What a community, full of people eager to share knowledge and expertise with each others, so inspiring. I mostly attended sessions about security best practices for containers and Kubernetes (that’s what excites me these days!). Secure Software Supply Chain (S3C) was almost mentioned everywhere, for good reasons.
Sigstore as a new standard for signing, verifying and protecting software, got its first own SigstoreCon as co-located event and hit the General Availability (GA) milestone.</description></item><item><title>Towards Easier, More Secure Signature Technology for the Java Ecosystem with Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/towards-easier-more-secure-signature-technology-for-the-java-ecosystem-with-sigstore-60d6a02490a8/</link><pubDate>Sat, 04 Feb 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/towards-easier-more-secure-signature-technology-for-the-java-ecosystem-with-sigstore-60d6a02490a8/</guid><description>In October 2022, the Sigstore project announced the General Availability of its free software signing service giving open source communities access to production-grade services for artifact signing and verification. As the project matures, so do the language client integrations that are actively being developed. In January 2023, sigstore-python announced the 1.0 version of Sigstore for Python.
The Java community has always taken a mature approach to security. So it should come as no surprise that there is plenty of activity towards integrating Sigstore into the existing ecosystem and offering first-class support for software signing and verification with Sigstore.</description></item><item><title>Sigstore January Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-january-roundup-09isdj30idoj/</link><pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-january-roundup-09isdj30idoj/</guid><description>This month, we are thrilled to have announced the 1.0 release of sigstore-python. This project started a year ago to provide a Sigstore-compatible client similar to cosign, but built entirely with Python and easily adoptable by the Python ecosystem.
A big thank you to all the contributors and maintainers for making it to 1.0! Read more
Latest Blog Posts Thank you to Andrew, Felix and Zachary for contributing the following blog posts this month.</description></item><item><title>A Guide to Running Sigstore Locally</title><link>https://lukehinds.github.io/sigstore-blog/a-guide-to-running-sigstore-locally-f312dfac0682/</link><pubDate>Tue, 24 Jan 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/a-guide-to-running-sigstore-locally-f312dfac0682/</guid><description>Co-authored with Andrew Block
A key concept in Sigstore is its availability. Anyone can leverage the hosted tooling to sign, publish and verify assets and incorporate it into their security processes.
In a corporate context with private repositories and private artifacts as well as restricted access to external resources, it must be questioned whether it makes sense to use the public Sigstore deployment. Sensitive information might be exposed. Given the principles of the Sigstore architecture, it cannot be erased or fenced off.</description></item><item><title>Announcing the 1.0 release of sigstore-python</title><link>https://lukehinds.github.io/sigstore-blog/announcing-the-1-0-release-of-sigstore-python-4f5d718b468d/</link><pubDate>Sat, 14 Jan 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/announcing-the-1-0-release-of-sigstore-python-4f5d718b468d/</guid><description>The sigstore-python project began 1 year ago in January 2022 with the goal of providing a Sigstore-compatible client similar to cosign, but built entirely with Python and easily adoptable by the Python ecosystem.
Today, thanks to the support of the community and work of 18 unique contributors, we’re excited to announce a usable and reference-quality 1.0 stable release of that client, which includes an importable Python API as well as a fully functional CLI.</description></item><item><title>Why you can’t use Sigstore without Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/why-you-cant-use-sigstore-without-sigstore-de1ed745f6fc/</link><pubDate>Fri, 06 Jan 2023 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/why-you-cant-use-sigstore-without-sigstore-de1ed745f6fc/</guid><description>Photo by C Dustin on Unsplash
I was delighted to see a recent preprint that mentioned Sigstore appear on the IACR’s Cryptology ePrint Archive. The reason that we published an academic paper, Sigstore: Software Signing for Everybody, was to encourage the scrutiny of the research community. Progress in the field of computer security only comes from the back-and-forth between proposed defenses and offensive analyses of those techniques, and we welcome third-party analysis of the project.</description></item><item><title>Sigstore December Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-december-roundup-7b5ebaac3442/</link><pubDate>Fri, 23 Dec 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-december-roundup-7b5ebaac3442/</guid><description>“And lo, in the land of software package management, a system was born to bring order and trust. Sigstore was its name, and its mission was to sign packages with short-lived certificates, validated by a powerful OIDC provider. These signed packages were then placed in a transparency database for all to see, like a holy book open for all to read and verify. Sigstore was a beacon of hope in a chaotic world, shining brightly as a protector of software integrity.</description></item><item><title>How to become the next Sigstore Evangelist?</title><link>https://lukehinds.github.io/sigstore-blog/how-to-become-the-next-sigstore-evangelist-9303ed297e54/</link><pubDate>Tue, 20 Dec 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/how-to-become-the-next-sigstore-evangelist-9303ed297e54/</guid><description>How to become the next Sigstore Evangelist? My story began by seeking a solution for signing container images at my company Trendyol. You will appreciate that few solutions were available at that time, almost two years ago. The only solution was DCT (Docker Content Trust) based on a Notary project, which is an implementation of the TUF (The Update Framework) specification, which allows you to verify both the integrity of the image and the publisher of all the data received from a registry by creating and using digital signatures.</description></item><item><title>Securing Your Software Supply Chain Without Changing Your DevOps Workflow</title><link>https://lukehinds.github.io/sigstore-blog/securing-your-software-supply-chain-without-changing-your-devops-workflow-e23393a5fffa/</link><pubDate>Thu, 15 Dec 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/securing-your-software-supply-chain-without-changing-your-devops-workflow-e23393a5fffa/</guid><description>*This is a Sigstore case study contributed by Tobias Trabelsi of* *DB Schenker*
DevOps has transformed the way software is built. The practice is ubiquitous, and organizations, big and small, use this approach to streamline development and accelerate release cycles. Many DevOps tools are created and supported by the open source community, but some companies shy away from these applications, preferring enterprise products with 24/7 support and established companies behind them.</description></item><item><title>Signatus, ergo securus? Who can sign what with TUF and Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/signatus-ergo-securus-who-can-sign-what-with-tuf-and-sigstore-ea4d3d84b8b6/</link><pubDate>Tue, 13 Dec 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/signatus-ergo-securus-who-can-sign-what-with-tuf-and-sigstore-ea4d3d84b8b6/</guid><description>Photo by Brett Jordan on Unsplash
Sigstore is an open-source project and service run by the OpenSSF to make signing software easy! Before Sigstore, a developer who wanted to sign software needed to manage a GPG key. With Sigstore, they can use their identity (for instance, a Gmail account) to sign. It also brings transparency: actions must be posted on a public log, so they can be audited to detect bad behavior and to analyze damage after-the-fact.</description></item><item><title>New Sigstore Landscape: Add your signed project</title><link>https://lukehinds.github.io/sigstore-blog/new-sigstore-landscape-add-your-signed-project-dda0517723b6/</link><pubDate>Wed, 30 Nov 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/new-sigstore-landscape-add-your-signed-project-dda0517723b6/</guid><description>A Sigstore section was added to the Open Source Security Foundation (OpenSSF)’s Landscape.
The aim of the Sigstore Landscape is to show the collection of technologies that make up the project’s growing ecosystem. This gives everyone a great overview of how everything fits together.
Landscape Sections The Sigstore Landscape currently has seven different sections.
Architecture/Spec Sigstore is a new standard for signing, verifying and protecting software. It can be used to make sure your software is what it claims to be.</description></item><item><title>Using Sigstore to meet FedRAMP Compliance at Autodesk</title><link>https://lukehinds.github.io/sigstore-blog/using-sigstore-to-meet-fedramp-compliance-at-autodesk-6f645a920abc/</link><pubDate>Wed, 23 Nov 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/using-sigstore-to-meet-fedramp-compliance-at-autodesk-6f645a920abc/</guid><description>This is a Sigstore case study contributed by Jesse Sanford of Autodesk
In today’s *-as-a-Service world, platforms are everywhere. Products as complex as entire operating systems and as simple as shared libraries are built and maintained on them. As software engineers, we leverage them for common capabilities. This allows us to focus on our customer needs and leave other cross-cutting concerns to the subject matter experts. Typically, security and compliance capabilities are particularly well suited for being delegated to the platform.</description></item><item><title>'Sigstore: Software Signing For Everybody' has been published in the proceedings of the ACM Computer and Communications Security Conference</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-software-signing-for-everybody-has-been-published-in-the-proceedings-of-the-acm-bb7e7d679a73/</link><pubDate>Thu, 17 Nov 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-software-signing-for-everybody-has-been-published-in-the-proceedings-of-the-acm-bb7e7d679a73/</guid><description>Photo by Bank Phrom on Unsplash
Sigstore: Software Signing for Everybody has been published at the 2022 ACM Computer and Communications Security (CCS) conference in Los Angeles, CA, an academic computer security conference, featuring publications from research universities around the world and industry labs at organizations like Google, Microsoft, Meta, and Amazon. This peer-reviewed research paper describes Sigstore, its security model, some data about its usage, and potential applications and is freely available under a CC-BY 4.</description></item><item><title>Security by Default: How Verizon New Business Incubation Uses Sigstore to Demonstrate Provenance and Improve Customer Confidence</title><link>https://lukehinds.github.io/sigstore-blog/security-by-default-how-verizon-new-business-incubation-uses-sigstore-to-demonstrate-provenance-7beed5714738/</link><pubDate>Thu, 10 Nov 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/security-by-default-how-verizon-new-business-incubation-uses-sigstore-to-demonstrate-provenance-7beed5714738/</guid><description>This is a Sigstore case study contributed by Aaron Bacchi of Verizon
When people think of 5G networks, they typically think solely of the speed and bandwidth that distinguishes the 5G network from its predecessors. However, the real story is the innumerable applications and use cases that 5G makes possible. 5G technology can help entrepreneurs and enterprises create a host of new possibilities in the form of smart spaces — cities, buildings, and homes — where high-speed wireless connectivity, combined with robotics and automation tools, can transform the world we live in and the way we live in it.</description></item><item><title>Sigstore November Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-november-roundup-8a852cec10fc/</link><pubDate>Thu, 10 Nov 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-november-roundup-8a852cec10fc/</guid><description>Sigstore GA Sigstore is excited to announce General Availability (GA) for the Rekor transparency log and Fulcio certificate authority public benefit services! The community has been working hard all year to accomplish this milestone, and we are thrilled that open source communities can now confidently rely on Sigstore for production-grade stable services for artifact signing and verification.
Read the Full Post by the Technical Steering Committee
SigstoreCon Recap SigstoreCon on October 25 in Detroit was Sigstore’s first-ever event and we’re so happy to say that it was a success!</description></item><item><title>Sigstore Announces General Availability for Rekor and Fulcio</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-ga-ddd6ba67894d/</link><pubDate>Tue, 25 Oct 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-ga-ddd6ba67894d/</guid><description>Sigstore is excited to announce general availability (GA) for the Rekor transparency log and Fulcio certificate authority public benefit services! The community has been working hard all year to accomplish this milestone, and we are thrilled that open source communities can now confidently rely on Sigstore for production grade stable services for artifact signing and verification.
While the Sigstore community has maintained a public instance since early 2021, the services were operated on a best-effort basis and maintainers periodically had to make breaking changes or reset data.</description></item><item><title>Sigstore Proves That Effective Supply Chain Security Doesn’t Have to Hurt</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-proves-that-effective-supply-chain-security-doesnt-have-to-hurt-cf33cf9333c8/</link><pubDate>Sat, 22 Oct 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-proves-that-effective-supply-chain-security-doesnt-have-to-hurt-cf33cf9333c8/</guid><description>This is a Sigstore case study contributed by Brandon Gulla, CTO at Rancher Government Solutions
Traditionally, everyone in IT assumed good security had to hurt a little bit. If it didn’t hurt, security wasn’t strong enough. But computing trends in software supply chains have shifted in recent years, moving toward centralized development and software factories. When you have that common infrastructure throughout the organization, you can isolate a lot of that pain within the process — without too much developer interaction and disruption.</description></item><item><title>Sigstore October Roundup</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-october-roundup-80d476308b75/</link><pubDate>Wed, 12 Oct 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-october-roundup-80d476308b75/</guid><description>Technical Steering Committee: New Member Thank you, Dan Lorenc, for your time on the Technical Steering Committee (TSC)! Sigstore is where it is today thanks to your help.
We also want to give a big welcome to Priya Wadhwa who is replacing Dan on the TSC! We know you’ll also be great at moving Sigstore in the right direction.
SigstoreCon The SigstoreCon program has been announced!
We are thrilled to have representatives from 14 different companies speaking at the event, namely: Autodesk, Chainguard, Cycode, Datadog, Edgeless Systems, GitHub, Google, IBM Research, InfluxData, Nirmata, Red Hat, Trail of Bits, Upgrade, and VMware.</description></item><item><title>How Sigstore quickly patched an upstream vulnerability</title><link>https://lukehinds.github.io/sigstore-blog/how-sigstore-quickly-patched-an-upstream-vulnerability-76ba84ef1122/</link><pubDate>Mon, 10 Oct 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/how-sigstore-quickly-patched-an-upstream-vulnerability-76ba84ef1122/</guid><description>Summary On October 3, 2022, Dex, the federated identity provider that Sigstore uses to issue identity tokens, published CVE-2022-39222 with a GitHub Security Advisory. Sigstore was vulnerable to this CVE, but we were able to quickly mitigate the vulnerability in June before an official fix was published.
Details On June 13, 2022, Joern Schneeweisz from the GitLab Security Research Team disclosed a vulnerability to Sigstore where an attacker executing a phishing campaign against a user can acquire a user’s identity token through a backchannel.</description></item><item><title>Contribute to Sigstore during Hacktoberfest 2022!</title><link>https://lukehinds.github.io/sigstore-blog/contribute-to-sigstore-during-hacktoberfest-2022-42315a41da5f/</link><pubDate>Fri, 30 Sep 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/contribute-to-sigstore-during-hacktoberfest-2022-42315a41da5f/</guid><description>This year, Sigstore is participating in Hacktoberfest for the first time!
What is Hacktoberfest? Hacktoberfest is a month-long celebration that encourages people to contribute to open source. Digital Ocean, along with its partners, hosts it every year.
Who can participate? Everyone and anyone is welcome to participate in Hacktoberfest (and to contribute to Sigstore).
The first 40,000 participants (maintainers and contributors) who complete Hacktoberfest can elect to receive one of two prizes: a tree planted in their name, or the Hacktoberfest 2022 t-shirt.</description></item><item><title>A New Look for Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/a-new-look-for-sigstore-9dd38877e308/</link><pubDate>Wed, 21 Sep 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/a-new-look-for-sigstore-9dd38877e308/</guid><description>You may have noticed Sigstore has a brand new logo! And not just the main logo but there are new logos for Rekor, Cosign, Fulcio and Gitsign. As the community works towards GA, we also wanted to spend some time sprucing up the Sigstore brand! We’re happy to share the new Sigstore logos and color palette.
New Logo In November 2021, Sigstore joined the Open Source Security Foundation (OpenSSF) as a project.</description></item><item><title>SigstoreCon Program Announced</title><link>https://lukehinds.github.io/sigstore-blog/sigstorecon-program-announced-509efb918970/</link><pubDate>Wed, 14 Sep 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstorecon-program-announced-509efb918970/</guid><description>This year we are hosting the very first Sigtorecon in Detroit, Michigan as part of Kubecon + CloudNativeCon North America. The event will take place on October 25th 2022. SigstoreCon is a one-day vendor neutral conference organized by the Sigstore community and focused on all things Sigstore.
We’re happy to announce the program for the first-ever SigstoreCon is now ready!
Thank you to everyone who took the time to submit a talk.</description></item><item><title>Sigstore Update — September 2022</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-update-september-2022-bb7a25a3d287/</link><pubDate>Thu, 08 Sep 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-update-september-2022-bb7a25a3d287/</guid><description>SigstoreCon The SigstoreCon call-for-papers closed last month and the program committee has been busy ranking the 23 great submissions received. Many thanks to all who submitted talks. And thanks to our program committee members: Priya Wadhwa, Lily Sturman, Appu Goundan, Jacques Chester, and Batuhan Apaydin.
The program will be announced on September 13. We hope to see you at SigstoreCon our first official event, on October 25 in Detroit, in co-location with KubeCon + CloudNativeCon North America.</description></item><item><title>Signing and Securing Confidential Kubernetes Clusters in the Cloud with Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/signing-and-securing-confidential-kubernetes-clusters-in-the-cloud-with-sigstore-aceac3034e70/</link><pubDate>Thu, 11 Aug 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/signing-and-securing-confidential-kubernetes-clusters-in-the-cloud-with-sigstore-aceac3034e70/</guid><description>This is a Sigstore case study contributed by Fabian Kammel of Edgeless Systems
Confidential computing is an exciting new technology that can help make the public cloud more secure. It protects data stored on leased third-party infrastructure and ensures nobody modifies or intercepts it, whether it resides on the cloud or is being routed to or from your internal assets. But it’s also vital that security solutions like those of Edgeless Systems are secure themselves.</description></item><item><title>Sigstore Update — August 2022</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-update-august-2022-813ac2c7c9ef/</link><pubDate>Tue, 09 Aug 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-update-august-2022-813ac2c7c9ef/</guid><description>It has been very busy in the Sigstore community over the past few weeks with lots of activity and initiatives progressing at speed. With so many exciting things happening it’s hard to keep up, but here’s a summary of the highlights from the past month.
NPM set to adopt Sigstore GitHub just announced a new request for comments (RFC) for linking packages to their source and build environment for the npm package manager.</description></item><item><title>Verify cosign signatures in go using sigstore/sigstore</title><link>https://lukehinds.github.io/sigstore-blog/verify-cosign-signatures-in-go-using-sigstore-sigstore-672222fc24d9/</link><pubDate>Tue, 09 Aug 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/verify-cosign-signatures-in-go-using-sigstore-sigstore-672222fc24d9/</guid><description>After integrating cosign into the release process of Constellation’s CLI, I also wanted to improve the supply chain security of our metadata that are used for attestation.
Using cosign CLI for signing and verifying blobs or container images is a well documented process. The sigstore/sigstore project is the common go library for all sigstore services and clients and has documented public functions, but I was unable to find examples on how to use them together.</description></item><item><title>Adopting Sigstore Incrementally</title><link>https://lukehinds.github.io/sigstore-blog/adopting-sigstore-incrementally-1b56a69b8c15/</link><pubDate>Tue, 02 Aug 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/adopting-sigstore-incrementally-1b56a69b8c15/</guid><description>Developers, package maintainers, and enterprises that would like to adopt Sigstore may already sign published artifacts. Signers may have existing procedures to securely store and use signing keys. Sigstore can be used to sign artifacts with existing self-managed, long-lived signing keys. Sigstore provides a simple user experience for signing, verification, and generating structured signature metadata for artifacts and container signatures. Sigstore also offers a community-operated, free-to-use transparency log for auditing signature generation.</description></item><item><title>Is Sigstore Ready for a Post-Quantum World?</title><link>https://lukehinds.github.io/sigstore-blog/is-sigstore-ready-for-a-post-quantum-world-82c9166985af/</link><pubDate>Sun, 17 Jul 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/is-sigstore-ready-for-a-post-quantum-world-82c9166985af/</guid><description>Photo by Anton Maksimov 5642.su on Unsplash
A couple of weeks back, NIST made big news in the cryptographic community by announcing that they have selected four quantum-resistant encryption and digital signature algorithms for standardization. In recent years, worries about the threats that quantum computers pose to current encryption algorithms have precipitated a major effort to establish a “post-quantum” (PQ) cryptographic toolkit. NIST’s 99-page full report, which reflects six years of work by a group of expert cryptographers details the algorithms and their performance and security characteristics However, the report omits the answer to the question on every Sigstore user’s mind: is Sigstore ready for a post-quantum world?</description></item><item><title>sigstore, blockchain vs transparency logs</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-blockchain-vs-transparency-logs-d673ea41a9be/</link><pubDate>Mon, 30 May 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-blockchain-vs-transparency-logs-d673ea41a9be/</guid><description>Co-authored by Luke Hinds (Red Hat) and Prof Santiago Torres-Arias (Purdue University).
Disclaimer: The following is representative of the authors views, and not necessarily that of the sigstore community.
*“Why did you chose to use a transparency log and not a blockchain?”*
We get this question often, so we figured it’s best to address this head on. It could be best summarised as *‘why would we use blockchain?*’ as opposed to ‘*why did we not use blockchain?</description></item><item><title>Privacy in Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/privacy-in-sigstore-57cac15af0d0/</link><pubDate>Sat, 28 May 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/privacy-in-sigstore-57cac15af0d0/</guid><description>Photo by Tim Mossholder on Unsplash
By default, the keyless signing flow for Sigstore exposes a user’s email:
$ rekor-cli search --email zack@example.com \ # not my real email! | wc -l Found matching entries (listed by UUID): 112 Specifically, a user logs in to Fulcio with OIDC. Fulcio issues a short-lived certificate with the SAN set to your email address as reported by the OIDC identity provider, even if your email is not typically exposed on that service itself (for instance, your GitHub email will be exposed, even though it’s not generally public).</description></item><item><title>Don’t Panic: A Playbook for Handling Account Compromise with Sigstore</title><link>https://lukehinds.github.io/sigstore-blog/dont-panic-a-playbook-for-handling-account-compromise-with-sigstore-ee299dca5144/</link><pubDate>Mon, 25 Apr 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/dont-panic-a-playbook-for-handling-account-compromise-with-sigstore-ee299dca5144/</guid><description>Photo by Tonik on Unsplash
Despite your best efforts, you may no longer trust artifacts, keys, or identities when signing software. A container might turn out to have vulnerabilities, a key might be lost, or worse: a trusted account could be compromised.
There’s a myth that Sigstore makes revocation harder; in fact, the opposite is true! While it is true that the signatures on software are stored forever, software verification using Sigstore does support artifact revocation.</description></item><item><title>How to verify container images with Kyverno using KMS, Cosign, and Workload Identity</title><link>https://lukehinds.github.io/sigstore-blog/how-to-verify-container-images-with-kyverno-using-kms-cosign-and-workload-identity-1e07d2b85061/</link><pubDate>Mon, 25 Apr 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/how-to-verify-container-images-with-kyverno-using-kms-cosign-and-workload-identity-1e07d2b85061/</guid><description>Securing our software supply chains has become more critical with the rise of software supply chain attacks. Also, over the past few years, container adoption has increased too. In the light of these pieces of information, it has grown the need to sign container images to help prevent supply chain attacks. In addition, most of the containers we are using today, even if we use them in production environments, are vulnerable to supply chain attacks.</description></item><item><title>Sigstore ❤ Ruby!</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-ruby-ce3591838fe8/</link><pubDate>Fri, 28 Jan 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-ruby-ce3591838fe8/</guid><description>We started the Sigstore project with a goal of making key management, certificates, and digital signatures accessible and easy to use for every developer and language community. It’s incredibly exciting to see our tooling and services used by new ecosystems, so we were thrilled to see the recent RFC from Shopify around improving the signing mechanisms on RubyGems using Sigstore.
On behalf of the Sigstore community, we’d like to affirm that we’re here to help with this RFC in any way we can!</description></item><item><title>Sigstore: Bring-your-own sTUF with TUF</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-bring-your-own-stuf-with-tuf-40febfd2badd/</link><pubDate>Wed, 19 Jan 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-bring-your-own-stuf-with-tuf-40febfd2badd/</guid><description>Users of Sigstore may want to leverage Sigstore tools and infrastructure, but may not want want to rely on Sigstore’s root of trust or all of the components of the public infrastructure. For example, a company may want to maintain a private transparency log for all internal build information but only make entries to a public log for published releases. Or, a user may not want to include their email addresses in a public certificate transparency log.</description></item><item><title>Celebrating 1,000,000 entries in Rekor</title><link>https://lukehinds.github.io/sigstore-blog/celebrating-1-000-000-entries-in-rekor-1950b7c150df/</link><pubDate>Mon, 10 Jan 2022 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/celebrating-1-000-000-entries-in-rekor-1950b7c150df/</guid><description>We’ve finally reached a million entries! We hit a million entries by the end of 2021:
rekor-cli get — log-index 1000000 LogID: c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d Index: 1000000 IntegratedTime: 2021–12–27T21:34:27Z UUID: abb93264122dc2eb6da3ac77957978dda3ceb3521ab52cdff8490b23eaf791c1
As a double milestone — the turn of the year and the next order of magnitude — this is a good opportunity to look into what’s become of the Sigstore ecosystem since its inception. Throughout the last year, we’ve seen a lot of different initiatives, new types of signatures added, tools, major features, and more from the whole community.</description></item><item><title>Spooky Updates for Sigstore!</title><link>https://lukehinds.github.io/sigstore-blog/spooky-october-updates-for-sigstore-87a2b72172c1/</link><pubDate>Fri, 29 Oct 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/spooky-october-updates-for-sigstore-87a2b72172c1/</guid><description>October is almost done, so it’s time for another update! The supply chains are clearly haunted, so this one has a spooky theme.
The community is still growing quickly, and the fancy new “Contributor Strength” dashboard reflects it!
In other numbers, we’re at 820 commits from 85 committers, and our slack channel has reached 710 members! Keep the PRs coming everyone!
The Sigstore talk at Kubecon went very well, and the Sigstore booth was a huge success!</description></item><item><title>Sigstore project update — September 2021</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-project-update-september-2021-799162b5a686/</link><pubDate>Fri, 01 Oct 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-project-update-september-2021-799162b5a686/</guid><description>Well another month has passed and as per usual in the sigstore world, a lot has happened!
Since our last update in August we have over double the amount of contributors working on sigstore! There has been a leap from 46 to 98! wow!
KubeCon NA 20201 sigstore will be at KubeCon North America with it’s own booth, so if you’re in person at the event, come and say hi! We will be at booth number S86</description></item><item><title>Sigstore Project Update — August 2021</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-project-update-august-2021-1fad6d12b8dc/</link><pubDate>Tue, 31 Aug 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-project-update-august-2021-1fad6d12b8dc/</guid><description>Welcome to our project update for August.
As always the community is continuing to expand. We are now close to 600 members in our slack workspace. We now have 46 contributors and are growing each day.
The month of August saw 254 commits and 526k lines of code were changed!
Lots of exciting things are happening, read more for our project updates and our presence at KubeCon, NA.
cosign Cosign hit 1.</description></item><item><title>It’s ten o’clock, do you know where your private keys are?</title><link>https://lukehinds.github.io/sigstore-blog/its-ten-o-clock-do-you-know-where-your-private-keys-are-5c869cf53234/</link><pubDate>Tue, 03 Aug 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/its-ten-o-clock-do-you-know-where-your-private-keys-are-5c869cf53234/</guid><description>Short-lived certificates are great — a short lifetime removes the need for complicated revocation policies and reduces an attacker’s window of opportunity. Yet using short-lived certificates in the software supply chain brings a lifetime problem: how can users trust artifacts after the certificate’s expiration? Repeatedly signing artifacts and requesting certificates is tedious. Really, distributors only need to prove that artifacts were signed when the certificate was valid… with timestamps! Enter SigStore’s new, free, open-source RFC 3161 timestamping service on the transparency log Rekor!</description></item><item><title>Cosign 1.0!</title><link>https://lukehinds.github.io/sigstore-blog/cosign-1-0-e82f006f7bc4/</link><pubDate>Wed, 28 Jul 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-1-0-e82f006f7bc4/</guid><description>The cosign project started in February 2021 with a goal of making it easy to sign and verify containers on any OCI registry today. The community support has been incredible! We’ve added 7 maintainers from 5 organizations, and have merged 394 commits from 32 contributors across 10 organizations. Cosign has been tested on 13 OCI registries and is now packaged in five different package managers. We’ve cut seven releases over six months and are now thrilled to declare our first general availability release, cosign 1.</description></item><item><title>Cosign 1.0</title><link>https://lukehinds.github.io/sigstore-blog/cosign-1-0-605771a05410/</link><pubDate>Tue, 20 Jul 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-1-0-605771a05410/</guid><description>It’s happening! Cosign’s 1.0 release is slated for July 28. If you were curious before but were hesitant about a pre-release project, now’s a good time to try it out and leave some comments.
For the initial release we plan on supporting: * Signing images with KMS (GCP, AWS, Azure, Vault), YubiKeys, and locally stored keys * Verifying image signatures using the same, plus public keys specified by URL * Verifying images in Dockerfiles * Uploading &amp;amp; signing arbitrary blobs (and 📄✍🏻👨🏻‍🦳 🇺🇸SBOMs🦅) * Stable APIs in pkg/ for integrating Cosign into build systems and policy engines</description></item><item><title>Sigstore June Update!</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-june-update-6b9c52f86e9d/</link><pubDate>Wed, 30 Jun 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-june-update-6b9c52f86e9d/</guid><description>Another month, another set of exciting updates! The Sigstore community has been working at a ferocious pace to harden our platforms and tools, while working on the larger picture of supply-chain security. The pieces are coming together, and the bigger vision of OSS supply chain transparency is getting a little less blurry.
This means the Sigstore community is starting to engage deeper in our peer communities as we integrate and share knowledge in both directions.</description></item><item><title>A New Kind of Trust Root</title><link>https://lukehinds.github.io/sigstore-blog/a-new-kind-of-trust-root-f11eeeed92ef/</link><pubDate>Tue, 08 Jun 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/a-new-kind-of-trust-root-f11eeeed92ef/</guid><description>I’m thrilled to announce that the Sigstore community is holding our first Root Key ceremony on June 18th at 2pm Eastern, and I’m even more thrilled to announce that it will be hosted LIVE by the always incredible DanPOP on his CloudNative.tv show, Spotlight Live. This Trust Root will eventually be used to secure the keys used by the entire Sigstore project, but more importantly we’re planning to make our trust root available for any open source project that wants to use it!</description></item><item><title>What’s Next for Sigstore?</title><link>https://lukehinds.github.io/sigstore-blog/whats-next-for-sigstore-1969e7321f75/</link><pubDate>Sat, 29 May 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/whats-next-for-sigstore-1969e7321f75/</guid><description>Photo by Joshua Hoehne on Unsplash
If you’re new to the Sigstore project, we officially launched on March 9th 2021 with a mission of improving the open source supply chain by making it easy to sign and verify code. We’re planning to provide free tools, APIs, and services as a public-benefit/non-profit. This post is to give a quick recap of where we are today, where we’re headed and what we’re focusing on next.</description></item><item><title>The Update Framework and You</title><link>https://lukehinds.github.io/sigstore-blog/the-update-framework-and-you-2f5cbaa964d5/</link><pubDate>Tue, 18 May 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/the-update-framework-and-you-2f5cbaa964d5/</guid><description>Why does it need to be so TUF?
If you’re anything like me and spend time reading blog posts and GitHub discussions around how to securely package and release software, you’ve probably heard of The Update Framework. Unfortunately, if you’re actually anything like me it probably seemed overwhelming and confusing at first. This blog post explains the mental model I’ve built up for TUF, and some of the concepts that finally made it understandable and digest-able for me.</description></item><item><title>How to Sign a Release of OSS</title><link>https://lukehinds.github.io/sigstore-blog/how-to-sign-a-release-of-oss-e96ee94286fc/</link><pubDate>Mon, 17 May 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/how-to-sign-a-release-of-oss-e96ee94286fc/</guid><description>I’ve heard a TON of questions about how to sign an open source software release lately. Once you get past the impossible tooling/crypto questions, you quickly realize you’ve barely scratched the surface in complexity. These problems aren’t all specific to OSS, but community-driven projects do face some unique challenges that stretch beyond technical and into the philosophical realm.
What does it mean to sign a release? Who should do it? Where should the keys live?</description></item><item><title>Cosign Image Signatures</title><link>https://lukehinds.github.io/sigstore-blog/cosign-image-signatures-77bab238a93/</link><pubDate>Thu, 13 May 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-image-signatures-77bab238a93/</guid><description>The protocol and format explained!
(Updated June 5th 2021)
In my last post, I showed how cosign can be used to sign and verify container images today. In this post, I’ll explain how it works at each step of the way.
Life of a Cosign Signature We’ll start with cosign generate-key-pair .
This command creates an ECDSA-P256 key pair (a private and a public key). The public key bytes are encoded in a PKIX formatted file.</description></item><item><title>Cosign — Signed Container Images</title><link>https://lukehinds.github.io/sigstore-blog/cosign-signed-container-images-c1016862618/</link><pubDate>Tue, 11 May 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/cosign-signed-container-images-c1016862618/</guid><description>I’ve seen a lot of questions about signing container images in the last few months, and unfortunately there aren’t many great options or answers today. So I decided to write a simple tool called cosign. It can sign container images! Here’s what it looks like to use:
You can get it installed and start signing containers in minutes. There are almost no configuration options, by design. There is only one supported signature algorithm (ECDSA-P256) and one payload format (Red Hat Simple Signing).</description></item><item><title>A Safer curl | bash ?</title><link>https://lukehinds.github.io/sigstore-blog/a-safer-curl-bash-7698c8125063/</link><pubDate>Sat, 01 May 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/a-safer-curl-bash-7698c8125063/</guid><description>This post is about using container registries (Docker registries, OCI registries, whatever you want to call them) for the storage and distribution of generic, non-container-related binary artifacts.
I explain the reasoning below, but first: code and demos
Demos! Here’s a quick walkthrough of a draft tool (still WIP!) to securely fetch published contents from an OCI registry, called sget. sgetis part of the sigstore project, and is a standalone client that allows you to retrieve scripts or binaries from any OCI registry.</description></item><item><title>Sigstore Project Update — April 2021</title><link>https://lukehinds.github.io/sigstore-blog/sigstore-project-update-april-2021-f01d7ea5c60e/</link><pubDate>Fri, 23 Apr 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/sigstore-project-update-april-2021-f01d7ea5c60e/</guid><description>Photo by Brett Jordan on Unsplash
Time flies in open source! This post provides a few updates on Sigstore since our last update in March. We’ve been lucky to continue welcoming new community members and contributors, with 39 contributors from over 15 companies and our Slack channel is rapidly approaching 300 members!
Let’s jump into some more project updates:
Rekor As mentioned above, the Rekor binary transparency log now natively supports signed JARs.</description></item><item><title>SSH is the new GPG</title><link>https://lukehinds.github.io/sigstore-blog/ssh-is-the-new-gpg-74b3c6cc51c0/</link><pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/ssh-is-the-new-gpg-74b3c6cc51c0/</guid><description>Not really. But Kind of?
Did you know that you probably already have a working PKI system for signing artifacts on your laptop today, with no keyservers, web-of-trust, or configuration? You can use it to sign files, and to find the public keys for other people and use them to verify files they signed.
So why aren’t more people using this? I think it’s just gone overlooked because it’s a relatively new feature in apretty old piece of software.</description></item><item><title>About</title><link>https://lukehinds.github.io/sigstore-blog/about/</link><pubDate>Sat, 08 Nov 2014 16:42:18 +0400</pubDate><guid>https://lukehinds.github.io/sigstore-blog/about/</guid><description>Learn more about the project at sigstore.dev.</description></item><item><title>Search</title><link>https://lukehinds.github.io/sigstore-blog/search/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lukehinds.github.io/sigstore-blog/search/</guid><description/></item></channel></rss>