Join us

ContentUpdates and recent posts about Sigstore..
Link
@kala shared a link, 3 months ago
FAUN.dev()

Reading across books with Claude Code

A custom LLM agent, built withClaude Codeand some hard-working CLI tools, chewed through 100+ nonfiction books by slicing them into 500-word semantic chunks - and then threading excerpt trails by topic. Under the hood: Chunk-topic indexes lived inSQLite. Topic embeddings flowed throughUMAPfor clust.. read more  

Reading across books with Claude Code
Link
@kala shared a link, 3 months ago
FAUN.dev()

The Complete Guide to CLAUDE.md

Claude Code just got smarter withCLAUDE.md- a project-level file that loads every time a session starts. Drop in your team's coding quirks, custom commands, naming rules, or traps to avoid. Claude reads it, remembers it, and quietly tailors responses to fit. Think of it likeAGENTS.md, seen in Cursor.. read more  

The Complete Guide to CLAUDE.md
Link
@kala shared a link, 3 months ago
FAUN.dev()

FinePDFs: Liberating 3T of the finest tokens from PDFs - a Hugging Face Space by HuggingFaceFW

Hugging Face introduces FinePDFs, a large open dataset built by extracting and cleaning text from millions of PDF documents, reaching trillions of tokens across many languages. The post explains how the pipeline handles messy PDF structure, layout noise, duplication, and low-quality content to produ.. read more  

Link
@devopslinks shared a link, 3 months ago
FAUN.dev()

What I Really Mean When I Say “Good Communication” in Incident Response

In the world of incidents,communication is key. Tailor messages for different audiences: be clear for business stakeholders, factual for IT management, and detailed for fellow responders. Don't let vagueness derail incident response - keep stakeholders informed with precise updates and clear expecta.. read more  

What I Really Mean When I Say “Good Communication” in Incident Response
Link
@devopslinks shared a link, 3 months ago
FAUN.dev()

Year in Review: Lessons From 12 Projects Patreon Shipped in 2025

Patreon engineers made massive bets in 2025, shipping code across all areas of the system and enabling impactful features like Autopilot's growth tools suite. Expanding Autopilot's scope, reach, and effectiveness was a challenge, especially guaranteeing recipient redemption after email delivery in a.. read more  

Link
@devopslinks shared a link, 3 months ago
FAUN.dev()

Monitoring & Observability: Using Logs, Metrics, Traces, and Alerts to Understand System Failures

Railway just leveled up its observability game. Now logs, metrics, and alerts all live in one tidy dashboard - clean and connected. Structured logs flow straight from stdout/stderr. Metrics pulse in real time. Alerts plug into monitors or deployment webhooks so teams catch firesbeforethey rage... read more  

Monitoring & Observability: Using Logs, Metrics, Traces, and Alerts to Understand System Failures
Link
@devopslinks shared a link, 3 months ago
FAUN.dev()

Making a micro Linux distro

A dev dives into building a barebones Linux distro for RISC-V using QEMU. Starts at the metal: compiles the kernel, wires up a no-frills init process, packs it all into an initramfs. Then levels up, drops inu-rootto swap out raw shell scripts for Go-powered userland tools. Adds network. Now it’s a f.. read more  

Making a micro Linux distro
News FAUN.dev() Team
@devopslinks shared an update, 3 months ago
FAUN.dev()

Canonical Introduces Minimal Ubuntu Pro: Smaller Images and Secure Cloud Workloads at Scale

Ubuntu GNU/Linux

Canonical has launched Minimal Ubuntu Pro, enhancing cloud security with lightweight images and robust features. Available on AWS, Azure, and Google Cloud, it offers minimized attack surfaces and long-term support.

Canonical Introduces Minimal Ubuntu Pro: Smaller Images and Secure Cloud Workloads at Scale
News FAUN.dev() Team
@varbear shared an update, 3 months ago
FAUN.dev()

AI's Dependence on Python Deepens as Anthropic Funds Core Ecosystem Work

Python

Anthropic invests $1.5 million in the Python Software Foundation to boost Python ecosystem security. The funding targets improvements in CPython and PyPI, including new tools for package review and malware datasets. It also supports the PSF's core activities and community initiatives.

AI's Dependence on Python Deepens as Anthropic Funds Core Ecosystem Work
News FAUN.dev() Team
@kala shared an update, 3 months ago
FAUN.dev()

Anthropic’s New "Economic Primitives" Reveal Who Uses Claude, for What, and How Well It Works

Anthropic's new Economic Index report introduces five "economic primitives" to measure *how* Claude is used: task complexity, user and AI skill level, use case (work, coursework, personal), autonomy, and task success - built from privacy-preserving classification of anonymized Claude.ai and first-party API transcripts from **November 2025**.

Anthropic’s New "Economic Primitives" Reveal Who Uses Claude, for What, and How Well It Works
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.