Gitsign – Keyless Git Commit Signing - Billy Lynch, Chainguard Inc

Описание к видео Gitsign – Keyless Git Commit Signing - Billy Lynch, Chainguard Inc

Gitsign – Keyless Git Commit Signing - Billy Lynch, Chainguard Inc

Tools like cosign have made it easy to improve software supply chains by making it simple to sign containers. But securing software supply chains means more than just signing containers! Ideally, every step in our release pipeline should be signed — from the artifacts we produce tracing back all the way to the source they originated from. In this talk, we'll take a look at Gitsign, one of Sigstore's latest projects that brings "keyless" signing to Git. We'll dive into how Gitsign works and how it fits into the rest of Sigstore, as well as how it can be applied to your development, CI/CD, and GitOps workflows.

Комментарии

Информация по комментариям в разработке