Hackernews posts about Sigstore
- Sigstore: Making sure your software is what it claims to be (www.sigstore.dev)
- OpenPubKey and Sigstore (blog.sigstore.dev)
- Signed Git Commits with Buildkite, Sigstore, Gitsign and OIDC (buildkite.com)
- Maven Central Adds Sigstore Signature Validation (socket.dev)
- NPM and Sigstore: Making JavaScript secure by default (www.chainguard.dev)
- sigstore-python 2.0 (blog.sigstore.dev)
- Gitsign: Keyless Git signing using Sigstore (github.com)
- Sigstore is an open source project for improving software supply chain security (docs.sigstore.dev)
- Elastic Stack container images signed with Sigstore (www.elastic.co)
- Sigstore: Roots of Trust for Software Artifacts (www.infoworld.com)
- Show HN: Trusty – Dependency Software Supply Chain Security (www.trustypkg.dev)
- An Introduction to Fulcio (edu.chainguard.dev)
- Bringing Privacy and Security Full Circle Through Automated Authentication (blog.sigstore.dev)