Two years after breaking out, Sigstore has settled into being the default signing story for OCI artifacts. A walk-through of where each major registry actually stands and what works in production.
Read moreTag: cosign
Practical DevSecOps with Sigstore and cosign
Signing images and artifacts with Sigstore is no longer exotic. How to integrate cosign into a real pipeline without turning signing into empty ritual.
Read more