Hackernews posts about Sigstore
- Show HN: Enact – A package manager for AI agent tools (enact.tools)
- Show HN: Signed lockfiles for MCP servers (MCPTrust) (github.com)
- Sigstore: Making sure your software is what it claims to be (www.sigstore.dev)
- Maven Central Adds Sigstore Signature Validation (socket.dev)
- Gitsign: Keyless Git signing using Sigstore (github.com)
- Sigstore is an open source project for improving software supply chain security (docs.sigstore.dev)
- An Introduction to Fulcio (edu.chainguard.dev)