Join us

ContentUpdates and recent posts about Sigstore..
Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

This New AI is 100x Faster at Reasoning Than ChatGPT

Sapient Intelligence’s HRM AI model challenges “bigger is better” in AI with a small 27M parameter design outperforming much larger models on reasoning tasks. The architecture mimics the brain, with a slow “planner” and rapid “worker,” achieving jaw-dropping results on benchmarks... read more  

Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

AWS deleted my 10-year account and all data without warning

AWS permanently nuked a 10-year customer account—data, backups, everything—after a payment verification failed. That alone broke their own 90-day retention policy. It gets messier. Looks like an internal script meant to run as a “dry run” went full send in production. Blame a Java CLI parsing edge .. read more  

AWS deleted my 10-year account and all data without warning
Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

A practical guide on how to use the GitHub MCP server

GitHub offers a managed MCP endpoint to simplify infrastructure management and streamline AI workflows, enhancing collaboration and code review processes... read more  

Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

Does platform engineering make sense for startups?

Platform engineering isn't just for the big dogs anymore. Startups are picking it up as astrategic edge, building tight, high-leverage tooling from day one. Think:templated CI/CD pipelines, plug-and-play infra modules, zero-handoff onboarding. Done right, these early bets smooth the path and keep d.. read more  

Does platform engineering make sense for startups?
Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

Proton launches free standalone cross-platform Authenticator app

Proton just droppedProton Authenticator, a free 2FA app that actually respects your privacy. It’s cross-platform, offline-friendly, and skips the usual junk—no ads, no trackers, no bait-and-lock-in. It’s gotend-to-end encryption, a biometric lock, and lets youexport TOTP seedslike it’s your data (b.. read more  

Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

How to use Terraform to generate secrets

Terraform just leveled up secret handling inAzure Key Vault. It now supports automated secret generation withrandom_password, plus full lifecycle control—rotation, expiration, and storage—baked right into your IaC. Secrets stay marked as sensitive. They're managed in one place. And thanks to Terraf.. read more  

How to use Terraform to generate secrets
Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

We built an MCP server so Claude can access your incidents

Incident.io dropped an open sourceMCP server in Gothat plugs Claude into their API using theModel Context Protocol. That means Claude can now ask questions, spin up incidents, and dig into timelines—just by talking. The server translates Claude’s prompts into REST calls, turning AI babble into real.. read more  

We built an MCP server so Claude can access your incidents
Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

AWS Lambda now supports GitHub Actions to simplify function deployment

AWS Lambda just got a smoother ride to prod. There’s now a nativeGitHub Actions integration—no more DIY scripts to ship your serverless. On commit, the new action packages your code, wires up IAM viaOIDC, and deploys using either.zip bundles or containers. All from a tidy, declarative GitHub workfl.. read more  

Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

Who does the unsexy but essential work for open source?

Oracle led the line-count race in the Linux 6.1 kernel release—beating out flashier open source names. Most of its work isn’t headline material. It’s deep-core stuff: memory management tweaks, block device updates, the quiet machinery real systems run on... read more  

Who does the unsexy but essential work for open source?
Link
@faun shared a link, 9 months, 1 week ago
FAUN.dev()

Terraform Validate Disagrees with Terraform Docs

Terraform’s CLI will throw errors on configs that match the docs—because your local provider schema might be stale or out of sync. Docs follow the latest release. Your machine might not. So even supported fields can break validation. Love that for us... read more  

Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.