sigstore retweeted
Cosign is a useful tool when signing containers by @projectsigstore / @openssf / @linuxfoundation - now it's really easy to install on Windows, macOS and Linux with pixi :)
sigstore retweeted
📣 Announcing v1.0 of the model-signing project, developed by the #OpenSSF AI/ML WG! This project enables signing + verifying ML models of any size/format using #sigstore, self-signed certs, or key pairs. Read the blog to learn more & get involved: openssf.org/blog/2025/04/04/…
sigstore retweeted
Replying to @projectsigstore
@projectsigstore signatures are now validated and distributed by Maven Central! sonatype.com/blog/central-pu…
sigstore retweeted
🏅 With the support of @chainguard_dev as a Gold Sponsor, #SigstoreCon is building a stronger foundation for secure software supply chains. 🙏 Thank you, Chainguard! Join us today: events.linuxfoundation.org/s…
#SupplyChainSecurity
sigstore retweeted
✨ Grateful for @StacklokHQ as a Gold Sponsor of #SigstoreCon! With their support, we’re pushing the boundaries of open source and supply chain security together.
Join us today: events.linuxfoundation.org/s…
#SupplyChainSecurity
sigstore retweeted
Huge thanks to @GoogleOSS for being a Platinum Sponsor of SigstoreCon! Their support for open source and supply chain security continues to drive the industry forward. 💪 #SigstoreCon #SupplyChainSecurity
events.linuxfoundation.org/s…
🚨 SigstoreCon: Supply Chain Day is almost here! Register now to join us on Nov 12 in Salt Lake City for a day of talks about Sigstore, SLSA, SBOMs, and more! events.linuxfoundation.org/s…
Join us at SigstoreCon: Supply Chain Day on Nov 12, co-located with KubeCon NA in SLC! Registration includes a day of engaging talks, lunch, and swag! events.linuxfoundation.org/s…
Announcing the schedule for SigstoreCon: Supply Chain Day! We're looking forward to talks on Sigstore development, package registry security, SBOMs, TUF, and more! Register now for Nov 12, co-located with Kubecon NA in Salt Lake City
events.linuxfoundation.org/s…
⏰ Reminder that the CFP for SigstoreCon closes tomorrow, September 18!
events.linuxfoundation.org/s…
The CFP deadline for SigstoreCon has been extended to Wednesday, September 18, 2024 at 11:59 pm Mountain Daylight Time (UTC-6).
events.linuxfoundation.org/s…
Reminder, the CFP for SigstoreCon closes on this Friday, September 13, 2024 at 11:59 pm Mountain Daylight Time (UTC-6) / 10:59 pm Pacific Daylight Time events.linuxfoundation.org/s…
⏰ Reminder folks, the CFP deadline is Sept 13, please submit your talks before then! events.linuxfoundation.org/s…
sigstore retweeted
On our last Securi-Taco Tuesday @puerco welcomed @rdcallaw & @haydentherapper from @Google's Open Source Security Team (GOSST) on to chat about how code signing and @projectsigstore secure the software supply chain.
Read the recap & watch the replay here:
stacklok.com/blog/securi-tac…
TSC Member @rdcallaw and community chair @haydentherapper from the Google OS Sec Team chatted with @puerco on the @StackLokHQ hosted 🌮 Securi-Taco Tuesdays 📺show. Lot's on sigstore and & software supply chain security. Catch it here: youtube.com/watch?v=JwfTCeBk…
sigstore retweeted
📣 Join us for SigstoreCon: Supply Chain Day!
📍Attendees will learn about simplifying signing & verification for digital artifacts using Sigstore, as well as related software supply chain efforts such as SLSA, and more! Learn more: openssf.org/blog/2024/08/14/…
#OSSSecurity
Join us for SigstoreCon: Supply Chain Day! Co-located with Kubecon NA 2024 in Salt Lake City. CFP now open events.linuxfoundation.org/s…
sigstore retweeted
Powered by @projectsigstore
Secure your cloud-native supply chain with #GitHub Artifact Attestations. Confirm your builds are actually what you want to build!
P.S. You can also achieve SLSA v1 Build Level 3
gh.io/AttestationsBlog
#cloudnative #supplychain #developer #secured
sigstore retweeted
Thank you @openuk_uk for the beautiful glass engraved award accepted on behalf of @projectsigstore and @controlplaneio for sponsoring the security category ❤️