Sigstore community today announced the first stable release of sigstore-python, improving software supply chain security and paving the way for other client implementations of Sigstore that are in earlier stages. . Sigstore is an open source project launched by Linux Foundation with the goal of providing free and stable services for all developers to easily sign, verify and protect their software projects. While code signing is a valuable tool to prevent hackers from co-opting patching systems and delivering malware, it is difficult to implement in open source projects given the complexity of key management. The sigstore-python, as part of the project and funded by Google's Open Source Security Team, aims to provide a Sigstore-compatible client like cosign but built entirely with Python and easily adoptable by the Python ecosystem. . Sigstore introduces a robust Python client aimed at bolstering software supply chain integrity while streamlining code signing processes for developers.. Sigstore, Software Signing, Code Protection. . LinuxSecurity.com Team
Sigstore that is backed by Google, Red Hat, GitHub, and other prominent organizations with an aim to secure the open-source software supply chain has reached general availability and issued the "v1.0" releases for their key software components. . This week Sigstore celebrated its general availability milestone and releasing the v1.0 software of their Rekor transparency log and Fulcio certificate authority software. Sigstore now considers itself to be production-grade for software artifact signing and verification. Sigstore provides the means of easily and cryptographically-backed means of signing code, verifying signatures using a transparency log, and monitoring of activity for safely vetting the software supply chain. The link for this article located at Phoronix is no longer available. . Recently, Sigstore marked a significant achievement with the announcement of its general availability and the launch of version 1.0 of its essential software tools.. Sigstore, Software Supply Chain, Code Signing, Open Source Security, Fulcio. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.