Join us

ContentUpdates and recent posts about Sigstore..
Story
@laura_garcia shared a post, 1ย month ago
Software Developer, RELIANOID

๐——๐—ฒ๐˜ƒ๐——๐—ฎ๐˜†๐˜€ โ€ข ๐——๐—ฒ๐˜ƒ๐—ข๐—ฝ๐˜€ ๐—ฃ๐—ฟ๐—ผ โ€ข ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐—ช๐—ถ๐˜€๐—ฒ๐—–๐—ผ๐—ป ๐—˜๐˜‚๐—ฟ๐—ผ๐—ฝ๐—ฒ

๐Ÿš€ ๐——๐—ฒ๐˜ƒ๐——๐—ฎ๐˜†๐˜€ โ€ข ๐——๐—ฒ๐˜ƒ๐—ข๐—ฝ๐˜€ ๐—ฃ๐—ฟ๐—ผ โ€ข ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐—ช๐—ถ๐˜€๐—ฒ๐—–๐—ผ๐—ป ๐—˜๐˜‚๐—ฟ๐—ผ๐—ฝ๐—ฒ ๐˜›๐˜ฉ๐˜ณ๐˜ฆ๐˜ฆ ๐˜ค๐˜ฐ๐˜ฏ๐˜ง๐˜ฆ๐˜ณ๐˜ฆ๐˜ฏ๐˜ค๐˜ฆ๐˜ด. ๐˜–๐˜ฏ๐˜ฆ ๐˜ฆ๐˜ค๐˜ฐ๐˜ด๐˜บ๐˜ด๐˜ต๐˜ฆ๐˜ฎ. ๐˜œ๐˜ฏ๐˜ญ๐˜ช๐˜ฎ๐˜ช๐˜ต๐˜ฆ๐˜ฅ ๐˜ช๐˜ฏ๐˜ฏ๐˜ฐ๐˜ท๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ. From May 19โ€“22, 2026, ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐—— will join the unified experience of ๐——๐—ฒ๐˜ƒ๐——๐—ฎ๐˜†๐˜€, ๐——๐—ฒ๐˜ƒ๐—ข๐—ฝ๐˜€ ๐—ฃ๐—ฟ๐—ผ, and ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐—ช๐—ถ๐˜€๐—ฒ๐—–๐—ผ๐—ป ๐—˜๐˜‚๐—ฟ๐—ผ๐—ฝ๐—ฒ in Vilnius. A unique event bringing together developers, DevOps engineers, cybersecu..

devdays_devops_pro_cyberwisecon_europe_vilnius_2026_relianoid
ย Activity
@harshilmalvi started using tool Microsoft Power Platform , 1ย month ago.
ย Activity
@harshilmalvi started using tool CloudSuite , 1ย month ago.
ย Activity
@mashka posted an event AI Is Already Inside Your SDLC. Now What? by Xygeni , 1ย month ago.
Link
@mfahlandt shared a link, 1ย month ago
Customer Delivery Architect, Kubermatic

Last Week in Cloud Native

Last Week in Cloud Native (LWCN) is a weekly newsletter dedicated to keeping the Cloud Native community informed about the latest releases, news, and developments in the CNCF ecosystem.

๐Ÿ“… Published: every Monday

๐ŸŒ Language: English

๐Ÿ’ถ Price: free, no paywall

๐Ÿง‘โ€๐Ÿ’ป Publisher: Mario Fahlandt

We believe staying current with the rapidly evolving Cloud Native landscape shouldnโ€™t require hours of research. LWCN distills the most important updates from across the ecosystem into a concise, actionable weekly digest โ€” written in a neutral, journalistic tone, with no marketing fluff.

Last Week in Cloud Native
Story
@laura_garcia shared a post, 1ย month ago
Software Developer, RELIANOID

๐—ก๐—ฒ๐˜„ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—”๐—ฑ๐˜ƒ๐—ถ๐˜€๐—ผ๐—ฟ๐˜†: ๐——๐—ถ๐—ฟ๐˜๐˜† ๐—™๐—ฟ๐—ฎ๐—ด (๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฏ๐Ÿฎ๐Ÿด๐Ÿฐ & ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฏ๐Ÿฑ๐Ÿฌ๐Ÿฌ)

๐Ÿšจ ๐—ก๐—ฒ๐˜„ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—”๐—ฑ๐˜ƒ๐—ถ๐˜€๐—ผ๐—ฟ๐˜†: ๐——๐—ถ๐—ฟ๐˜๐˜† ๐—™๐—ฟ๐—ฎ๐—ด (๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฏ๐Ÿฎ๐Ÿด๐Ÿฐ & ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฐ๐Ÿฏ๐Ÿฑ๐Ÿฌ๐Ÿฌ) Two newly disclosed ๐˜“๐˜ช๐˜ฏ๐˜ถ๐˜น ๐˜ฌ๐˜ฆ๐˜ณ๐˜ฏ๐˜ฆ๐˜ญ ๐˜ท๐˜ถ๐˜ญ๐˜ฏ๐˜ฆ๐˜ณ๐˜ข๐˜ฃ๐˜ช๐˜ญ๐˜ช๐˜ต๐˜ช๐˜ฆ๐˜ด โ€” collectively known as Dirty Frag โ€” impact specific ๐—œ๐—ฃ๐˜€๐—ฒ๐—ฐ/๐—ซ๐—™๐—ฅ๐—  ๐—ฝ๐—ฎ๐—ฐ๐—ธ๐—ฒ๐˜ ๐—ต๐—ฎ๐—ป๐—ฑ๐—น๐—ถ๐—ป๐—ด ๐—ฝ๐—ฎ๐˜๐—ต๐˜€ in Linux. What does this mean for RELIANOID users? โœ… ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐—— ๐—น๐—ผ๐—ฎ๐—ฑ ๐—ฏ๐—ฎ๐—น๐—ฎ๐—ป๐—ฐ๐—ถ๐—ป๐—ด ๐—ฑ๐—ฒ๐—ฝ๐—น๐—ผ๐˜†๐—บ๐—ฒ๐—ป๐˜๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ก..

Link
@varbear shared a link, 1ย month, 1ย week ago
FAUN.dev()

Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace

Orca Security researchers identified four attack primitives in an AI coding-agent skills marketplace: install-count inflation without authentication, security scans at creation and popularity thresholds, same-name overrides without user alerts, and bulk updates without per-skill review or version pi.. read more ย 

Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace
Link
@varbear shared a link, 1ย month, 1ย week ago
FAUN.dev()

Adventures in 30 Years in Engineering Productivity

Carlos Arguelles collects a decade of writing on engineering productivity at Microsoft, Amazon, and Google, covering monorepo versus microrepo CI/CD philosophies, hermetic test environments, ML-based bug deduplication, code coverage debates, and the AI-driven shift toward autonomous validation of ge.. read more ย 

Adventures in 30 Years in Engineering Productivity
Link
@varbear shared a link, 1ย month, 1ย week ago
FAUN.dev()

I Deleted My Clever Code and the Database Got Better

A first-person walkthrough of rewriting an embedded key-value store after a friend spotted that the lock-free ring buffer was writing to a slot before claiming ownership, with the rebuilt single-mutex version 76 lines smaller, more correct, and explicit about every tradeoff (fsync on every write, no.. read more ย 

Link
@varbear shared a link, 1ย month, 1ย week ago
FAUN.dev()

6 Multi-Agent Orchestration Design Patterns Every Developer Should Know

Chris Pietschmann walks through six multi-agent orchestration patterns (sequential pipeline, fan-out/fan-in, hierarchical delegation, consensus, event-driven, iterative refinement) and the state management primitives that let them compose... read more ย 

6 Multi-Agent Orchestration Design Patterns Every Developer Should Know
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.