Главная
Study mode:
on
1
Intro
2
Agenda
3
Supply chain security
4
Software signing and provenance
5
Technology behind Sigstore
6
Community stats
7
Demos
8
Demo 1 Go Application
9
FullCo
10
Transparency Log
11
Cosign
12
Demo
13
Open Identity Flow
14
JSON Web Token
15
Inclusion Proof
Description:
Explore the journey of Sigstore, a Linux Foundation project providing non-profit software security cryptographic signing services, in this informative conference talk. Learn about the project's inception, current status, and future direction as presented by Bob Callaway from Red Hat and Dan Lorenc from Google. Discover how Sigstore, often compared to 'Let's Encrypt' for software signing, is being implemented to protect Kubernetes release container images and verify them directly in Kubernetes release infrastructure. Gain insights into the project's adoption by various communities such as Python, RubyGems, WebAssembly, and Maven. Delve into topics including supply chain security, software signing and provenance, and the technology behind Sigstore. Witness live demonstrations of a Go application, FullCoTransparency Log, Cosign, and Open Identity Flow. Understand the role of JSON Web Tokens and Inclusion Proofs in the Sigstore ecosystem.

Sigstore: Evolution and Future of Software Security Signing

CNCF [Cloud Native Computing Foundation]
Add to list