sigstore is a non-profit , public good software signing service funded under the OpenSSF. https://nitter.cf/t.co/HYGAJ06Z11 sigstore@infosec.exchange

Joined March 2021
Cosign is a useful tool when signing containers by @projectsigstore / @openssf / @linuxfoundation - now it's really easy to install on Windows, macOS and Linux with pixi :)
Interested in Software Supply Chain Security? We are! That's why we helped to get `cosign` on conda-forge: `cosign` can be used to sign container images or other artifacts with `sigstore`, and you can now easily install it with `pixi global install cosign` 🎉
2
9
1,117
sigstore retweeted
📣 Announcing v1.0 of the model-signing project, developed by the #OpenSSF AI/ML WG! This project enables signing + verifying ML models of any size/format using #sigstore, self-signed certs, or key pairs. Read the blog to learn more & get involved: openssf.org/blog/2025/04/04/…
4
1
14
1,088
sigstore retweeted
✨ Grateful for @StacklokHQ as a Gold Sponsor of #SigstoreCon! With their support, we’re pushing the boundaries of open source and supply chain security together. Join us today: events.linuxfoundation.org/s… #SupplyChainSecurity
1
1
3
494
sigstore retweeted
Huge thanks to @GoogleOSS for being a Platinum Sponsor of SigstoreCon! Their support for open source and supply chain security continues to drive the industry forward. 💪 #SigstoreCon #SupplyChainSecurity events.linuxfoundation.org/s…
4
5
874
Announcing the schedule for SigstoreCon: Supply Chain Day! We're looking forward to talks on Sigstore development, package registry security, SBOMs, TUF, and more! Register now for Nov 12, co-located with Kubecon NA in Salt Lake City events.linuxfoundation.org/s…
6
1
14
2,301
On our last Securi-Taco Tuesday @puerco welcomed @rdcallaw & @haydentherapper from @Google's Open Source Security Team (GOSST) on to chat about how code signing and @projectsigstore secure the software supply chain. Read the recap & watch the replay here: stacklok.com/blog/securi-tac…
7
9
1,169
TSC Member @rdcallaw and community chair @haydentherapper from the Google OS Sec Team chatted with @puerco on the @StackLokHQ hosted 🌮 Securi-Taco Tuesdays 📺show. Lot's on sigstore and & software supply chain security. Catch it here: youtube.com/watch?v=JwfTCeBk…
2
5
468
sigstore retweeted
📣 Join us for SigstoreCon: Supply Chain Day! 📍Attendees will learn about simplifying signing & verification for digital artifacts using Sigstore, as well as related software supply chain efforts such as SLSA, and more! Learn more: openssf.org/blog/2024/08/14/… #OSSSecurity
1
8
14
1,126
Thank you @openuk_uk for the beautiful glass engraved award accepted on behalf of @projectsigstore and @controlplaneio for sponsoring the security category ❤️
3
5
21
1,072