# Not all that's signed is secure: Verify the right way with TUF and Sigstore

DevFeed: [Not all that's signed is secure: Verify the right way with TUF and Sigstore](<https://devfeed.tech/articles/not-all-that-s-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore-13189.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/not-all-thats-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore>)

Published: 2023-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [verification](<https://devfeed.tech/tags/verification.md>)

## AI overview

The article summarizes a talk on using Sigstore and The Update Framework (TUF) to create verification policies for securing software supply chains. It explains that signing alone does not provide sufficient protection, because verifying the wrong way can leave systems vulnerable to supply chain attacks. It presents TUF as a way to build flexible verification policies and describes how Sigstore supports easier signing with rigorous verification.

## Source excerpt

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains