Software Engineering KB

Home

❯

08 Security

❯

04 Supply Chain Security

❯

01 Concept

❯

Artifact Signing

Artifact Signing

Feb 10, 20261 min read

  • supply-chain-security
  • artifact-signing

Artifact Signing

← Back to Software Supply Chain

Cryptographically signing build artifacts to verify their integrity and provenance. Sigstore and cosign provide keyless signing for containers and other artifacts. Signed artifacts enable consumers to verify that the artifact was built by a trusted source and has not been tampered with.

Key Properties

  • Sigstore
  • cosign
  • Provenance Verification

supply-chain-security artifact-signing


Graph View

  • Artifact Signing
  • Key Properties

Backlinks

  • Software Engineering - Map of Content
  • Software Supply Chain

Created with Quartz v4.5.2 © 2026

  • GitHub