tuf

Sigstore Announcement: New TUF Trust Root and Client Compatibility

New TUF Trust Root We are planning to publish a new TUF trust root for Sigstore. This update does not contain any functional changes, but it does update to the latest version of the TUF specification. This means that older clients may not be able to load it properly. The current compatibility is as follows: Cosign Releases >= v2.2.0 (v2.2.0 released Aug 31st 2023) work. Older Cosign clients (< v2.2.0) will not work v1.

Signatus, ergo securus? Who can sign what with TUF and Sigstore

Photo by Brett Jordan on Unsplash Sigstore is an open-source project and service run by the OpenSSF to make signing software easy! Before Sigstore, a developer who wanted to sign software needed to manage a GPG key. With Sigstore, they can use their identity (for instance, a Gmail account) to sign. It also brings transparency: actions must be posted on a public log, so they can be audited to detect bad behavior and to analyze damage after-the-fact.