Join us

ContentUpdates and recent posts about Sigstore..
 Activity
@aleonrangel gave 🐾 to Difference between Agile and Scrum , 1 month, 2 weeks ago.
Story
@laura_garcia shared a post, 1 month, 2 weeks ago
Software Developer, RELIANOID

🔐 Reminder: Azure MFA Enforcement Is Now in Place

Some time ago, Microsoft announced and enforced mandatory multifactor authentication (MFA) for all Azure tenants performing resource management actions. 👉 This marked a clear turning point: MFA is no longer optional — it’s a requirement. At RELIANOID, we shared how this change reinforces the need to..

Link
@varbear shared a link, 1 month, 2 weeks ago
FAUN.dev()

How to build internal developer tools with a small team

A fresh way to think about internal dev tooling: three axes,width(new features),depth(polish and stability), andpreparation(future-ready architecture). Instead of treating tradeoffs as binary, the model maps them as vectors in a shared space. Less tug-of-war. More informed roadmap moves... read more  

How to build internal developer tools with a small team
Link
@varbear shared a link, 1 month, 2 weeks ago
FAUN.dev()

The Mac Malware of 2025 👾

The 2025 macOS malware scene leveled up hard. Thinkmodular infostealers, built for stealth, slipping in with staged loaders, encrypted configs, and slick social engineering - fake updates, bogus job interviews, even sketchy terminal promos like “ClickFix.” Attackers leaned onAppleScript,JXA, andGo-b.. read more  

The Mac Malware of 2025 👾
Link
@varbear shared a link, 1 month, 2 weeks ago
FAUN.dev()

Web development is fun again

A seasoned dev takes a hard look at today’s messy full-stack reality: scattered tools, niche deep-dives, and burnout baked into the job. ButAI coding assistantsflipped the script. They help offload overhead, mimic pro-level workflows, and sanity-check the code. Now this dev moves across frontend and.. read more  

Web development is fun again
Link
@varbear shared a link, 1 month, 2 weeks ago
FAUN.dev()

How Browsers Work

An interactive open-source guide breaks down browser internals with slick, step-through models coveringDNS resolution,TCP handshakes, andHTML parsing. It walks through the browser'ssequential pipeline- from URL to DOM - blending protocol deep-dives with hands-on visuals you can poke at... read more  

Link
@kaptain shared a link, 1 month, 2 weeks ago
FAUN.dev()

v1.35: Introducing Workload Aware Scheduling

Kubernetes v1.35 is shifting gears. The newWorkload APIand earlygang schedulingsupport bring group-first thinking, schedule Pods as a unit, or not at all. They’ve thrown inopportunistic batchingtoo. It’s in Beta. It speeds up clusters juggling loads of identical Pods by skipping repeat feasibility c.. read more  

Link
@kaptain shared a link, 1 month, 2 weeks ago
FAUN.dev()

From Cluster UI to Operational Plane: Lessons from the Kubernetes Dashboard Deprecation

The official Kubernetes Dashboard has been deprecated. This reflects the shift in Kubernetes operations towards multi-cluster environments, GitOps workflows, and strict access controls. Modern Kubernetes environments require application-aware, RBAC-first operational tools that work across clusters a.. read more  

Link
@kaptain shared a link, 1 month, 2 weeks ago
FAUN.dev()

Kubernetes Was Overkill. We Moved to Docker Compose and Saved 60 Hours.

A small team rolled back their Kubernetes move after six months in the weeds. The setup tanked productivity, bloated infra costs, and turned simple deploys into a slog. They ditched it, brought back Docker Compose, and chopped deploy time from 45 minutes to 4. That one change freed up 60+ engineerin.. read more  

Link
@kaptain shared a link, 1 month, 2 weeks ago
FAUN.dev()

Kubernetes by Example

K8s by Exampleis likeGo by Example, but for YAML and Kubernetes. It’s packed with annotated manifests that show real deployment, scaling, and self-healing patterns, stuff you'd actually use in prod... read more  

Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.