Sigstore Proves That Effective Supply Chain Security Doesn’t Have to Hurt

This is a Sigstore case study contributed by Brandon Gulla, CTO at Rancher Government Solutions Traditionally, everyone in IT assumed good security had to hurt a little bit. If it didn’t hurt, security wasn’t strong enough. But computing trends in software supply chains have shifted in recent years, moving toward centralized development and software factories. When you have that common infrastructure throughout the organization, you can isolate a lot of that pain within the process — without too much developer interaction and disruption.

Sigstore October Roundup

Technical Steering Committee: New Member Thank you, Dan Lorenc, for your time on the Technical Steering Committee (TSC)! Sigstore is where it is today thanks to your help. We also want to give a big welcome to Priya Wadhwa who is replacing Dan on the TSC! We know you’ll also be great at moving Sigstore in the right direction. SigstoreCon The SigstoreCon program has been announced! We are thrilled to have representatives from 14 different companies speaking at the event, namely: Autodesk, Chainguard, Cycode, Datadog, Edgeless Systems, GitHub, Google, IBM Research, InfluxData, Nirmata, Red Hat, Trail of Bits, Upgrade, and VMware.

How Sigstore quickly patched an upstream vulnerability

Summary On October 3, 2022, Dex, the federated identity provider that Sigstore uses to issue identity tokens, published CVE-2022-39222 with a GitHub Security Advisory. Sigstore was vulnerable to this CVE, but we were able to quickly mitigate the vulnerability in June before an official fix was published. Details On June 13, 2022, Joern Schneeweisz from the GitLab Security Research Team disclosed a vulnerability to Sigstore where an attacker executing a phishing campaign against a user can acquire a user’s identity token through a backchannel.

Contribute to Sigstore during Hacktoberfest 2022!

This year, Sigstore is participating in Hacktoberfest for the first time! What is Hacktoberfest? Hacktoberfest is a month-long celebration that encourages people to contribute to open source. Digital Ocean, along with its partners, hosts it every year. Who can participate? Everyone and anyone is welcome to participate in Hacktoberfest (and to contribute to Sigstore). The first 40,000 participants (maintainers and contributors) who complete Hacktoberfest can elect to receive one of two prizes: a tree planted in their name, or the Hacktoberfest 2022 t-shirt.

A New Look for Sigstore

You may have noticed Sigstore has a brand new logo! And not just the main logo but there are new logos for Rekor, Cosign, Fulcio and Gitsign. As the community works towards GA, we also wanted to spend some time sprucing up the Sigstore brand! We’re happy to share the new Sigstore logos and color palette. New Logo In November 2021, Sigstore joined the Open Source Security Foundation (OpenSSF) as a project.