# software artifact signing

Published articles for software artifact signing.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Elastic partners with Chainguard on Software Supply Chain security and SLSA assessment

DevFeed: [Elastic partners with Chainguard on Software Supply Chain security and SLSA assessment](<https://devfeed.tech/articles/elastic-partners-with-chainguard-on-software-supply-chain-security-and-slsa-assessment-13026.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/elastic-partners-with-chainguard-on-software-supply-chain-security-and-slsa-assessment>)

Published: 2023-07-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-assessement](<https://devfeed.tech/tags/slsa-assessement.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Elastic partnered with Chainguard to assess its software supply chain using the SLSA framework. The article describes supply-chain risks across source, build, dependencies, and packages, and highlights software artifact signing with Sigstore as a security measure.

### Source excerpt

Elastic and Chainguard unite for enhanced software supply chain security and SLSA assessment.

## Introducing "Speranza": Enhancing software signing with privacy and usability

DevFeed: [Introducing "Speranza": Enhancing software signing with privacy and usability](<https://devfeed.tech/articles/introducing-speranza-enhancing-software-signing-with-privacy-and-usability-13121.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-speranza-enhancing-software-signing-with-privacy-and-usability>)

Published: 2023-05-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard Labs introduces Speranza, a research project for usable, privacy-friendly software signing. The article explains how it aims to improve software supply chain security while addressing the usability problems of long-lived cryptographic keys and the privacy risks of exposing maintainers' identities or metadata. It also discusses potential applications in open source package repositories and enterprise deployments of Sigstore.

### Source excerpt

Chainguard Labs announces, "Speranza: Usable, privacy-friendly software signing," to help balance usability and privacy for software signing techniques.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.

## New Chainguard Academy tutorial: Cosign the manual way

DevFeed: [New Chainguard Academy tutorial: Cosign the manual way](<https://devfeed.tech/articles/new-chainguard-academy-tutorial-cosign-the-manual-way-13173.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-academy-tutorial-cosign-the-manual-way>)

Published: 2023-03-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [rekor](<https://devfeed.tech/tags/rekor.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [transparency-log](<https://devfeed.tech/tags/transparency-log.md>), [trust](<https://devfeed.tech/tags/trust.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>), [verify](<https://devfeed.tech/tags/verify.md>)

### AI overview

This article introduces a Chainguard Academy tutorial that explains Cosign's blob-signing capabilities. It covers generating an RSA key pair, signing data with SHA-256, uploading signatures to the Rekor transparency log, and verifying the signature.

### Source excerpt

New Chainguard Academy tutorial unpacks Cosign the manual way and explores Cosign's blob signing capabilities.