Join us

ContentUpdates and recent posts about Sigstore..
Link
@pushpakraut shared a link, 1ย month, 1ย week ago

how i deployed a secure harbor registry with https on rke1 rke2 real production setup

Story
@laura_garcia shared a post, 1ย month, 1ย week ago
Software Developer, RELIANOID

CVE-2026-31431 ("Copy Fail")

๐Ÿšจ CVE-2026-31431 ("Copy Fail") A Linux kernel flaw enabling reliable root privilege escalation from local access. ๐Ÿ” Affects most systems since ~2017 โš ๏ธ High impact, stealthy exploitation ๐Ÿ› ๏ธ Fix: Patch immediately & restrict AF_ALG if unused ๐Ÿ›ก๏ธ Mitigated in RELIANOID EE 8.6 and CE 7.10 ๐Ÿ‘‰ Technical tr..

Story
@alok00k shared a post, 1ย month, 1ย week ago

Why Functional Testing Is Still the Backbone of Software Quality

#Testingย  #functio...ย  #AIย  #Test Au...ย 

Functional testing ensures software behaves according to business and user requirements by validating complete workflows, APIs, and application behavior. As modern applications become more API-driven and distributed, functional testing plays a critical role in preventing broken user experiences and production failures. Automated functional testing integrated with CI/CD pipelines helps teams release software faster while maintaining reliability and quality.

functional__testing
Story
@koukibadr shared a post, 1ย month, 1ย week ago
Mobile Developer, Nventive

Localize Your Flutter App with Gemini

Why localize your app? Think about it, ignoring international users is like making a fire meme and forgetting to post it online - what's the point? But don't worry, we hear you screaming Fear not, for Gemini is here to be your Yoda in the localization swamp. We'll tackle all your app translation..

Localize Flutter App
ย Activity
@ruchi-sharma created an organization Nimble AppGenie , 1ย month, 2ย weeks ago.
Story WrapPixel Team
@sanjayjoshi shared a post, 1ย month, 2ย weeks ago

8+ Best Shadcn Collapsible Component Examples for React & Next.js

Shadcn Collapsible components offer a flexible, non-interruptive way to manage secondary content in React and Next.js projects. Unlike accordions or dialogs, they keep users in context while reducing UI clutter. Key variations include sidebar menus, API key managers, and file trees, all of which benefit from Tailwind CSS styling and full ARIA accessibility.

Collapsible OG Img
ย Activity
@alihenryofficial started using tool SAP Commerce Cloud , 1ย month, 2ย weeks ago.
ย Activity
@alihenryofficial started using tool Google Publisher Tag , 1ย month, 2ย weeks ago.
Story
@laura_garcia shared a post, 1ย month, 2ย weeks ago
Software Developer, RELIANOID

๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ ๐—ถ๐—ป ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐—— ๐—˜๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ ๐—˜๐—ฑ๐—ถ๐˜๐—ถ๐—ผ๐—ป

๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ + ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐—— = ๐˜ด๐˜ต๐˜ณ๐˜ฐ๐˜ฏ๐˜จ๐˜ฆ๐˜ณ ๐˜ต๐˜ณ๐˜ถ๐˜ด๐˜ต from the very first instruction executed. Here's a practical guide on ๐—ต๐—ผ๐˜„ ๐˜๐—ผ ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—•๐—ผ๐—ผ๐˜ ๐—ถ๐—ป ๐—ฅ๐—˜๐—Ÿ๐—œ๐—”๐—ก๐—ข๐—œ๐—— ๐—˜๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ ๐—˜๐—ฑ๐—ถ๐˜๐—ถ๐—ผ๐—ป using the standard shim + MOK approach. ๐Ÿ” Whatโ€™s inside: - Why Secure Boot canโ€™t be enabled on first install - Step-by-step MOK enr..

ย Activity
@sanjayjoshi gave ๐Ÿพ to How To Make a Fast Dynamic Language Interpreter , 1ย month, 2ย weeks ago.
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.