The Linux Foundation's "sigstore" project
The Linux Foundation's "sigstore" project
Posted Mar 11, 2021 7:20 UTC (Thu) by fwiesweg (guest, #116364)In reply to: The Linux Foundation's "sigstore" project by shemminger
Parent article: The Linux Foundation's "sigstore" project
Like everything we do, security-related work is iterative in nature and this is but a single building stone to secure the supply chain. Further steps are required and might include many things, from reviewed packages (signed by the reviewers, too), automatic content analyses (so packages are signed by those systems, too), etc., but there'd be no point in all of that if you can't even guarantee that the sources package arrives on your disk without having been tampered with somewhere between you and the maintainer/reviewer. So something like sigstore is a first and necessary, but in itself still insufficient step.
