Join us

ContentUpdates and recent posts about Sigstore..
News FAUN.dev() Team
@varbear shared an update, 7 months ago
FAUN.dev()

Google Expands AI Vibe-Coding App Opal to 15 More Countries

Opal

Google expands its AI vibe-coding app Opal to 15 more countries, enhancing global access to no-code web app creation with improved debugging and performance.

Google Expands AI Vibe-Coding App Opal to 15 More Countries
News FAUN.dev() Team
@kaptain shared an update, 7 months ago
FAUN.dev()

Azure Outage: Kubernetes Crash Hits Teams, Minecraft in EMEA Regions

Kubernetes

A Kubernetes crash caused a major Azure outage, impacting Teams and Minecraft in EMEA, with Microsoft working to restore services.

Azure Outage: Kubernetes Crash Hits Teams, Minecraft in EMEA Regions
Link
@anjali shared a link, 7 months ago
Customer Marketing Manager, Last9

15 PHP APM Tools Worth Using in 2025

Compare 15 PHP APM tools for 2025 — from open-source options to managed platforms — and find what fits your performance needs.

php_apm
Story
@viktoriiagolovtseva shared a post, 7 months ago

A Hands-On Guide To Jira Service Management [2025]

Be it a small, mid-sized, or large business — improving the customer journey can improve customer satisfaction and boost revenue byup to 15%. JIRA by Atlassian provides a centralized platform where your customers can report bugs, reach out for assistance, explore your knowledge base, and submit requ..

Screenshot 2025-10-10 at 13.44.54
Story
@laura_garcia shared a post, 7 months ago
Software Developer, RELIANOID

🎉 We’ve just hit 1,600+ followers on LinkedIn! 🎉

A big thank you to everyone who’s part of our growing community of professionals passionate about Application Delivery, Load Balancing, and Cybersecurity. 💪 If you haven’t joined us yet, follow us on LinkedIn 👉 https://www.linkedin.com/company/relianoid/..

1600 followers RELIANOID
Story
@viktoriiagolovtseva shared a post, 7 months ago

How to Use an Email Campaign Template in Jira to Launch Campaigns Faster

Great email campaigns run on clockwork processes. And Jira templates can serve as a backbone for creating a smooth workflow. Using an email campaign template will speed up and streamline campaign preparation, enabling you to kick-start the process in mere seconds. Another benefit is that your team will gain a ready action plan with clearly defined stages and dependencies. With a well-documented process and better-organized teamwork, you will be able to prepare email campaigns more quickly and efficiently.

In this blog post, we provide you with customizable email campaign templates and explain how to use them in Jira.

Link
@anjali shared a link, 7 months ago
Customer Marketing Manager, Last9

How OpenTelemetry Auto-Instrumentation Works

OpenTelemetry auto-instrumentation uses runtime hooks and agents to collect telemetry without code changes—covering most modern stacks.

otel_auto_instrumentation
Link
@anjali shared a link, 7 months ago
Customer Marketing Manager, Last9

How to Scale Prometheus APM for Modern Applications

Learn how to scale Prometheus APM for growing systems with practical strategies to keep queries fast and monitoring efficient.

node
Link Xygeni Team
@mashka shared a link, 7 months ago
Paid Acquisition and Growth Marketing, xygeni

Join our Upcomping Online Podcast Episode on AI Unleashed: Navigating Emerging Threats and Defenses in AppSec

AI is transforming Application Security, powering both new attacks and smarter defenses.
Join us to explore how AI-driven threats, such as polymorphic malware, prompt injections, and model tampering, are reshaping Application Security (AppSec) and how to defend against them.

📅 Date: October 22nd
⏰ Time: 16:00 (CEST) / 10:00 (EDT)
🎙 Speakers:

Atanas Nikolov — DevSecOps Expert @ RNDC Bulgaria

Jesús Cuadrado — CPO @ Xygeni

🔗 Register here to join live → https://www.linkedin.com/events/aiunleashed-navigatingemergingt7382047771396104192/

Why Attend:
💠 Learn the latest AI-powered AppSec threats
💠 Discover practical AI-driven defense techniques
💠 Strengthen your AppSec strategy for the AI era

Join us!

SafeDev Talk - AI Unleashed Navigating Threats & Defenses (1)
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.