Join us

ContentUpdates and recent posts about Sigstore..
ย Activity
@cristiandeluxe started using tool NGINX Ingress Controller , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool Next.js , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool Laravel , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool Kubectl , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool Google GKE , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool GNU/Linux , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool Docker , 4ย weeks, 2ย days ago.
ย Activity
@cristiandeluxe started using tool cPanel , 4ย weeks, 2ย days ago.
Story
@laura_garcia shared a post, 1ย month ago
Software Developer, RELIANOID

RELIANOID Live Demo

Behind every successful deployment, thereโ€™s a ๐—ฑ๐—ฒ๐—ฑ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐—ฑ ๐˜๐—ฒ๐—ฎ๐—บ ๐˜„๐—ผ๐—ฟ๐—ธ๐—ถ๐—ป๐—ด ๐—ฐ๐—น๐—ผ๐˜€๐—ฒ๐—น๐˜† ๐˜„๐—ถ๐˜๐—ต ๐—ฐ๐˜‚๐˜€๐˜๐—ผ๐—บ๐—ฒ๐—ฟ๐˜€ to ๐™™๐™š๐™ก๐™ž๐™ซ๐™š๐™ง ๐™ฉ๐™๐™š ๐™ง๐™ž๐™œ๐™๐™ฉ ๐™จ๐™ค๐™ก๐™ช๐™ฉ๐™ž๐™ค๐™ฃ ๐™–๐™ฉ ๐™ฉ๐™๐™š ๐™ง๐™ž๐™œ๐™๐™ฉ ๐™ฉ๐™ž๐™ข๐™š. Todayโ€™s ๐—น๐—ถ๐˜ƒ๐—ฒ ๐—ฑ๐—ฒ๐—บ๐—ผ ๐˜€๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป is a great example of how our engineers go beyond technology โ€” providing ๐—ต๐—ฎ๐—ป๐—ฑ๐˜€-๐—ผ๐—ป ๐—ฒ๐˜…๐—ฝ๐—ฒ๐—ฟ๐˜๐—ถ๐˜€๐—ฒ, ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜๐—ถ๐—บ๐—ฒ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฎ๐—ป๐—ฐ๐—ฒ, and a ๐—ณ๐˜‚๐—น๐—น๐˜† ๐—ฝ๐—ฒ๐—ฟ๐˜€๐—ผ๐—ป๐—ฎ..

RELIANOID LIVE DEMO
Story
@laura_garcia shared a post, 1ย month ago
Software Developer, RELIANOID

๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐˜€ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—œ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐—ถ๐—ฎ๐—น ๐—ฆ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ

๐Ÿšจ ๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐˜€ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—œ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐—ถ๐—ฎ๐—น ๐—ฆ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ ๐Ÿšจ According to recent industry reports, 2025 saw a significant rise in high-severity cyber incidents across critical sectors: ๐Ÿ”น IT: 23% ๐Ÿ”น Government: 18% ๐Ÿ”น Industrial: 18% The industrial and food sectors are becoming increasingly attractive..

high-severity incident per industries graph
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.