Join us

ContentUpdates and recent posts about Sigstore..
Story Trending
@laura_garcia shared a post, 3ย months, 3ย weeks ago
Software Developer, RELIANOID

๐Ÿš€ ๐—ฆ๐—–๐—”๐—Ÿ๐—˜ ๐Ÿฎ๐Ÿฏ๐˜… โ€“ ๐—ฆ๐—ผ๐˜‚๐˜๐—ต๐—ฒ๐—ฟ๐—ป ๐—–๐—ฎ๐—น๐—ถ๐—ณ๐—ผ๐—ฟ๐—ป๐—ถ๐—ฎ ๐—Ÿ๐—ถ๐—ป๐˜‚๐˜… ๐—˜๐˜…๐—ฝ๐—ผ

๐Ÿ“… March 5โ€“8, 2026 | ๐Ÿ“ Pasadena, California SCALE 23x โ€“ Southern California Linux Expo is back โ€” North Americaโ€™s largest community-run open source conference! Four days of: ๐Ÿ”น Open source innovation ๐Ÿ”น DevOps & cloud-native deep dives ๐Ÿ”น Cybersecurity insights ๐Ÿ”น Hands-on technical workshops ๐Ÿ”น Real commu..

scale_23x_event_2026_pasadena_relianoid
Story
@laura_garcia shared a post, 3ย months, 3ย weeks ago
Software Developer, RELIANOID

Weโ€™re heading to Big Data & AI World 2026

Weโ€™re heading to Big Data & AI World 2026 ๐Ÿ“ 4โ€“5 March 2026 | London Part of Tech Show London 2026, this event brings together data and AI leaders focused on responsible, scalable AI and measurable business outcomes. At RELIANOID, we enable secure, high-performance infrastructures ready for AI-driven..

big_data_ai_world_london_2026_relianoid
Link
@kala shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

Realtime Prompting Guide

OpenAI shipsgpt-realtimeand declares GA for theRealtime API. It's a speech-to-speech model that tightens instruction-following, steadiestool calling, and lifts voice fidelity. Latency drops. True realtime agents become possible. The release prescribesprompt skeletons,JSON envelopetool outputs,sessio.. read more ย 

Realtime Prompting Guide
Link
@kala shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

Introducing helm

helm usesTypeScripttypes to registerskillsas typed functions with structured I/O. Permissions follow a clear precedence: exactโ†’wildcardโ†’skillโ†’global. Agents get a keywordsearchtool and a code-execution tool that runs JS inside anSESsandbox. A recursiveproxyforwards calls overIPCto the parent, which .. read more ย 

Introducing helm
Link
@kala shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

Do you need an MCP to build your native app?

Do you need an MCP to build your native app? Surprisingly, modern agents succeed either way. The real difference is how much time, cost, and context you waste along the way... read more ย 

Do you need an MCP to build your native app?
Link
@kala shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

The Pentagon is making a mistake by threatening Anthropic

Anthropic's Claude Gov, optimized for national security uses, has fewer restrictions than regular versions. The Pentagon is threatening retaliation if Anthropic does not waive these restrictions by Friday, including invoking the Defense Production Act or declaring Anthropic a supply chain risk. Anth.. read more ย 

Link
@kaptain shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

Before You Migrate: Five Surprising Ingress-NGINX Behaviors You Need to Know

The K8s blog exposesIngress-NGINXdefaults that clash withGateway API. These include case-insensitive prefix regexes. Host-wide annotation effects. Path rewrites. Slash redirects. URL normalization. Kubernetes retiresIngress-NGINXinMarch 2026.Gateway API 1.5graduatesListenerSetand theHTTPRoute CORS.. read more ย 

Link
@kaptain shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

From Chaos to Clarity: How We Built a Self-Healing CI/CD Pipeline That Talks to JIRA

Transitioning JIRA tickets to trigger deployments was key for this team struggling with manual deploys, leading to significant savings in time and reduction in errors. The architecture involved a JIRA Controller Pipeline, a Project Deployment Pipeline, and a JIRA Manager Pipeline, all aimed at seaml.. read more ย 

From Chaos to Clarity: How We Built a Self-Healing CI/CD Pipeline That Talks to JIRA
Link
@kaptain shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

Spotlight on SIG Architecture: API Governance

Kubernetes SIG Architectureโ€™s API Governance crew is tightening the screws on stability, consistency, and cross-cutting sanity across the whole API surface. Not just REST. Theyโ€™re eyeing the overlooked stuff too - CLI flags, config formats, anything that shapes how users and tools touch the system. .. read more ย 

Link
@kaptain shared a link, 3ย months, 3ย weeks ago
FAUN.dev()

I Built a Production-Grade Kubernetes Platform in 48 Hours.

A dev built a production-grade Kubernetes platform in 48 hours, encountering challenges and solutions along the way. The setup included multiple layers such as infrastructure, cluster, platform, delivery, and observability, each requiring troubleshooting and adjustments. The process involved deployi.. read more ย 

I Built a Production-Grade Kubernetes Platform in 48 Hours.
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.