Kubernetes Taps Sigstore To Thwart Open Source Software Supply Chain Attacks
The Sigstore certificates are being used in the just-released Kubernetes version 1.24 and all future releases. According to founding Sigstore developer Dan Lorenc, a former member of Google’s open-source security team, the use of Sigstore certificates allows Kubernetes users to verify the authenticity and integrity of the distribution they’re using by “giving users the ability to verify signatures and have greater confidence in the origin of each and every deployed Kubernetes binary, source code bundle and container image....