Not all that’s signed is secure: Verify the right way with TUF and Sigstore
CYBERSECURITY FEATURED ANALYSIS

Not all that’s signed is secure: Verify the right way with TUF and Sigstore

SOURCE

Chainguard: Unchained

DATE

READ

1 min read

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains