Sigstore Announcement: New TUF Trust Root and Client Compatibility

New TUF Trust Root We are planning to publish a new TUF trust root for Sigstore. This update does not contain any functional changes, but it does update to the latest version of the TUF specification. This means that older clients may not be able to load it properly. The current compatibility is as follows: Cosign Releases >= v2.2.0 (v2.2.0 released Aug 31st 2023) work. Older Cosign clients (< v2.2.0) will not work v1.

Sigstore - An OpenSSF Graduated Project

Sigstore Graduates: A Monumental Step Towards Secure Software Supply chain security took a giant leap forward this month as Sigstore officially became a graduated project within the Open Source Security Foundation (OpenSSF). This milestone is a testament to Sigstore’s maturity, adoption, and its undeniable impact on making the creation and distribution of software more trustworthy. What is Sigstore? For those unfamiliar, Sigstore is a suite of tools designed to streamline secure software signing & verification of artifacts such as binaries, containers and attestations.

Sigstore February Roundup

Welcome to the February edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings. Events KubeCon Europe 2024 The next KubeCon Europe will be held on 19th – 22nd March. There are several Sigstore related talks and events planned for KubeCon Europe, including: Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev & Yonghe Zhao, Yahoo Navigating the Software Supply Chain Defense Landscape - Marina Moore & Aditya Sirish A Yelgundhalli, New York University Contribfest: Enable Additional Signing Mechanisms for TUF and in-toto: No Cryptography Skills Required Open Source Summit North America 2024 The next Open Source Summit North America will be held on April 16th – 18th

Sigstore January Roundup

Welcome to the January edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings. Events KubeCon Europe 2024 The next KubeCon Europe will be held on 19th – 22nd March. There are serveral Sigstore related talks and events planned for KubeCon Europe, including: Securing the Supply Chain with Sigstore Artifacts Signatures at Scale - Dmitry Savintsev & Yonghe Zhao, Yahoo Navigating the Software Supply Chain Defense Landscape - Marina Moore & Aditya Sirish A Yelgundhalli, New York University Contribfest: Enable Additional Signing Mechanisms for TUF and in-toto: No Cryptography Skills Required FOSDEM 2024 The next FOSDEM will be held in Brussels, Belgium on the 3rd & 4th February 2024 along with a talk on Sigstore and SLSA by John Viega.

Sigstore November Roundup

Welcome to the November edition of the Sigstore Roundup! This is a regular summary of Sigstore news, events, releases and other happenings. Sigstore Google Season of Docs 2023 Case Study A very comprehisive case study has been published on the Sigstore docs wiki about the Sigstore project’s participation in the 2023 program. Thank you Lisa Tagliaferri for all your hard work on this and making it a success! Latest Releases Rekor v1.