sigstore(@projectsigstore) 's Twitter Profileg
sigstore

@projectsigstore

sigstore is a non-profit , public good software signing service funded under the OpenSSF. https://t.co/HYGAJ06Z11 [email protected]

ID:1366293442574319617

calendar_today01-03-2021 07:45:40

1,0K Tweets

4,2K Followers

1 Following

Luke Hinds(@decodebytes) 's Twitter Profile Photo

Interesting tidbit; sigstore was originally going to be called 'rekor' (the entire ecosystem). I was chatting with the The Linux Foundation about donation at the time. We hit possible legal bumps as a traffic monitoring company used the name rekor...

account_circle
Jason(@ImJasonH) 's Twitter Profile Photo

Frederic 🧊 Branczyk @[email protected] This is a benefit of attaching signed provenance outside the image. We use sigstore and it works great.

Getting reproducible image builds was one of the (many!) reasons we built our own tools for it, more about it here chainguard.dev/unchained/desi…

account_circle
sigstore(@projectsigstore) 's Twitter Profile Photo

Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev & Yonghe Zhao, from Yahoo youtube.com/watch?v=Tp-t_7…

account_circle
OpenSSF(@openssf) 's Twitter Profile Photo

Supply chain security took a giant leap forward this month as Sigstore officially became a graduated project within the OpenSSF. This milestone is a testament to Sigstore’s maturity, adoption. Learn more about Sigstore & how to get involved: openssf.org/blog/2024/03/2…

Supply chain security took a giant leap forward this month as Sigstore officially became a graduated project within the OpenSSF. This milestone is a testament to Sigstore’s maturity, adoption. Learn more about Sigstore & how to get involved: openssf.org/blog/2024/03/2… #OSSSecurity
account_circle
sigstore(@projectsigstore) 's Twitter Profile Photo

Anyone using Cosign v1.x, please update to Cosign v2 or download the upcoming v1.13.3 release. We are rolling out a new TUF Trust Root blog.sigstore.dev/tuf-root-updat…

account_circle
Richard Seroter(@rseroter) 's Twitter Profile Photo

Care (even a little bit) about using verified software? Watch this InfoQ presentation (or read the transcript) to get smarter on the important sigstore effort.

infoq.com/presentations/…

account_circle
Orlin Vasilev(@OrlinVasilev) 's Twitter Profile Photo

Next week me and Valentin Hristev will speak about and how to secure deployments and how you can utilize Project Harbor build in features like signing with from sigstore and implement blocking if Aqua Trivy finds something 🧀 in the image! :)

Next week me and Valentin Hristev will speak about #containers and how to secure deployments and how you can utilize @project_harbor build in features like signing with #cosign from @projectsigstore and implement blocking if @AquaTrivy finds something 🧀 in the image! :) #meetup
account_circle
stacklok(@StackLokHQ) 's Twitter Profile Photo

Now in Minder—new ways to help you secure your artifacts. Configure custom / private sigstore instances; do more expressive provenance checks; and use our pre-built policies to secure GitHub Actions workflows. stacklok.com/blog/4-ways-to…

account_circle
OpenSSF(@openssf) 's Twitter Profile Photo

Sigstore is aimed to ensure privacy & scalability, integrates technologies for seamless signing, verification, & provenance checks. 🔏 Explore how Yahoo utilizes alongside Athenz as an internal Certificate Authority for container image security: openssf.org/case-studies/2…

account_circle
sigstore(@projectsigstore) 's Twitter Profile Photo

🚀 The sigstore-go library just cut its first release. The library now has sigstore bundle & rekor verification, Timestamp Authority verification , TUF support and more. Thanks to all community members working on this!
github.com/sigstore/sigst…

account_circle