skip to content

Artifact Signing & Sigstore

Signing binds a trusted identity to exact bytes, and keyless flows have replaced long-lived release keys. Interviewers probe the chain: OIDC identity, short-lived certificate, transparency log.

on this pageshow

explore

questions

page 2 of 2

How do you stop your set of accepted signing identities from becoming an unreviewable allowlist?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Give every accepted identity an owner, a justification, a scope and an expiry, then reconcile the list against what has actually signed anything recently. Additions are always urgent and removals never are, so the set ratchets unless expiry is the default.

open as a page

showing 31–31 of 31