Meaning
Open-source supply chain protections shield software images from unauthorized changes by using a public transparency ledger and automated signing services. Implementing sigstore container security allows organizations to verify that a container image was built by a specific person or process without managing a complex key infrastructure. It provides the tools needed to sign images and store the resulting proofs in a way that is easily searchable and verifiable by third parties.
This builds trust in the entire software distribution network.
Artifact Transparency
Every signing event is recorded in a tamper-proof log that can be audited by the public or internal security teams. The sigstore container security framework ensures that any attempt to replace a legitimate image with a malicious one is immediately detectable. This transparency is a requirement for securing modern open-source software.
Public Ledger
Records are maintained in a global ledger that serves as a single source of truth for software provenance. Using sigstore container security removes the need for developers to distribute public keys manually. It leverages existing identity providers to link signatures to real-world actors.
Distribution Safety
Distribution safety is improved when every image is traceable to a specific build event. Sigstore container security creates a chain of trust for users.