Sigstore Announcement: New TUF Trust Root and Client Compatibility

New TUF Trust Root We are planning to publish a new TUF trust root for Sigstore. This update does not contain any functional changes, but it does update to the latest version of the TUF specification. This means that older clients may not be able to load it properly. The current compatibility is as follows: Cosign Releases >= v2.2.0 (v2.2.0 released Aug 31st 2023) work. Older Cosign clients (< v2.2.0) will not work v1.

Sigstore February Roundup

Welcome to the February edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings. Events KubeCon Europe 2024 The next KubeCon Europe will be held on 19th – 22nd March. There are several Sigstore related talks and events planned for KubeCon Europe, including: Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev & Yonghe Zhao, Yahoo Navigating the Software Supply Chain Defense Landscape - Marina Moore & Aditya Sirish A Yelgundhalli, New York University Contribfest: Enable Additional Signing Mechanisms for TUF and in-toto: No Cryptography Skills Required Open Source Summit North America 2024 The next Open Source Summit North America will be held on April 16th – 18th

Sigstore January Roundup

Welcome to the January edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings. Events KubeCon Europe 2024 The next KubeCon Europe will be held on 19th – 22nd March. There are serveral Sigstore related talks and events planned for KubeCon Europe, including: Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev & Yonghe Zhao, Yahoo Navigating the Software Supply Chain Defense Landscape - Marina Moore & Aditya Sirish A Yelgundhalli, New York University Contribfest: Enable Additional Signing Mechanisms for TUF and in-toto: No Cryptography Skills Required FOSDEM 2024 The next FOSDEM will be held in Brussels, Belgium on the 3rd & 4th February 2024 along with a talk on Sigstore and SLSA by John Viega.

Sigstore November Roundup

Welcome to the November edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings. Sigstore Google Season of Docs 2023 Case Study A very comprehisive case study has been published on the Sigstore docs wiki about the Sigstore project’s participation in the 2023 program. Thank you Lisa Tagliaferri for all your hard work on this and making it a success! Latest Releases Rekor v1.

Announcing sigstore-go

Announcing sigstore-go Today we’re excited to announce a new open source library, sigstore-go, that represents the future of Sigstore’s support for the Go programming language. Since the beginning, Sigstore has been primarily written in Go but there has been a gap over the past year or so since we established the Protobufs-based bundle format: the de facto standard client (Cosign) lacks support for it. Cosign-the-library is also heavily focused on OCI use cases, which makes it difficult for library integrators who want to limit their implementations to core sign/verify flows and it also supports a wide variety of verification options, which creates potentially confusing duplication.

OpenPubkey and Sigstore

Disclaimer: The following is representative of the authors views, and not necessarily that of the sigstore community. OpenPubKey was announced October 4th by Docker and BastionZero as a new Linux Foundation project. It’s a new scheme for using OIDC providers to sign arbitrary objects. It bears a lot of resemblance to Sigstore, so I thought it would be worth taking some time to explain the differences, including some advantages and disadvantages.

npm's Sigstore-powered provenance goes GA

Last week saw the GA release of npm CLI’s native Sigstore functionality, a project over a year in the making. This is a tremendous milestone for the adoption of Sigstore in open source projects and represents huge progress in effecting a cultural shift toward expecting provenance to exist for software components. It also helps move npm toward the best practices articulated by the OpenSSF’s Securing Open Source Repos Working Group in their document “Build Provenance for All Package Registries”.

Announcing sigstore-python 2.0

We are delighted to announce the 2.0 release of sigstore-python, a Python client for signing and verifying Sigstore signatures! $ python -m pip install -U sigstore $ python -m sigstore --version sigstore 2.0.0 This release has been in the works for a while, and contains a number of significant improvements and breaking changes to both the sigstore CLI and Python APIs. We’ve also updated the official sigstore/gh-action-sigstore-python action to use the latest 2.

Trusted Time in Sigstore

Time in Sigstore Time is a critical component of Sigstore. It’s used to verify that a short-lived certificate issued by Fulcio was valid at a previous point, when the artifact was signed. As a reminder, the default signing flow for Sigstore clients includes the following: Signer requests an identity token from an OpenID Connect provider Signer generates an ephemeral keypair Signer sends the public key and identity token to Fulcio, Sigstore’s certificate authority Fulcio issues a short-lived (10 minute expiration) code-signing certificate Signer signs the artifact, and uploads the artifact, the certificate, and signature to Rekor, Sigstore’s transparency log During artifact verification, a client must verify the certificate.

Sigstore Announcement: No Longer Publishing Cosign Releases to GCS Bucket

We are announcing that we will stop publishing Cosign releases to the GCS bucket named cosign-releases. The current v2.1.1 release of Cosign is the last release that will be pushed to the bucket, and public access to the GCS bucket will be removed on October 31st, 2023. Why are we deprecating the GCS bucket? We are deprecating the GCS bucket because we already use GitHub in the Sigstore community, and it is a reliable and secure platform for hosting release artifacts.