Kubernetes To Use Sigstore To Stop Supply Chain Attacks

Share post:

Kubernetes will now add cryptographically signed signatures to protect users and organizations from supply chain attacks.

Access to the cryptographically signed signatures is via the Sigstore project created by the Linux Foundation.

Using sigstore certificates allows Kubernetes users to verify the authenticity and integrity of the distribution they are using.

According to founding Sigstore developer Dan Lorenc, the use of Sigstore certificates gives “users the ability to verify signatures and have greater confidence in the origin of each Kubernetes binary, source code bundle, and container image.”

Lorenc pointed out that Kubernetes’ adoption of Sigstore is part of its work on supply chain levels for Software Artifacts (SLSA). SLSA is a framework developed by Google for the internal protection of its software supply chain.

The Sigstore project is also aimed at Python developers. The aim of this project will be to release a new tool for signing Python packages as well as major package repositories such as Maven Central and RubyGems.

The sources for this piece include an article in ZDNet.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Canadian group gets $2.2 million to research AI threat detection for wireless networks

Ericsson Canada and three universities have been awarded funds by the National Cybersecurity

Proposed Canadian AI law ‘fundamentally flawed,’ Parliament told

A privacy lawyer said the proposed AI bill is vague and sets a dangerous precedent

Canada, U.S. sign international guidelines for safe AI development

Eighteen countries, including Canada, the U.S. and the U.K., today agreed on recommended guidelines to developers in their nations for the secure design, development, deployment, and operation of artificial intelligent systems. It’s the latest in a series of voluntary guardrails that nations are urging their public and private sectors to follow for overseeing AI in

Is OpenAI’s Q* Artificial General Intelligence?

OpenAI's latest model, Q* (pronounced Q Star), is raising eyebrows in the AI community as a potential milestone...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways