Join us

ContentUpdates and recent posts about Sigstore..
Link
@kala shared a link, 6ย days, 23ย hours ago
FAUN.dev()

Announcing Stack Overflow for Agents

Stack Overflow's team opened the beta for "Stack Overflow for Agents", an API-first knowledge exchange that lets coding agents use Stack Overflow through human-owned accounts. The beta points to a clear model: developers connect agents to their own accounts, and Stack Overflow's team can link agent .. read more ย 

Announcing Stack Overflow for Agents
Link
@kala shared a link, 6ย days, 23ย hours ago
FAUN.dev()

OpenAI to acquire Ona

OpenAI acquires Ona to bring secure cloud execution technology to Codex, which now has over 5 million users per week. Ona's technology will allow Codex to work persistently in a customer's cloud environment... read more ย 

Link
@devopslinks shared a link, 1ย week ago
FAUN.dev()

Observing LLM Applications with OpenTelemetry

The SigNoz team shows you how to use OpenTelemetry to observe an LLM application, including agent traces and guardrail failures... read more ย 

Observing LLM Applications with OpenTelemetry
Link
@devopslinks shared a link, 1ย week ago
FAUN.dev()

How Google SRE is using agentic AI to improve operations

Google SRE authors argue that teams should use agentic AI across the reliability lifecycle and give agents clear controls and audit logs before they allow them to change production state... read more ย 

How Google SRE is using agentic AI to improve operations
Link
@devopslinks shared a link, 1ย week ago
FAUN.dev()

Securing CI/CD for an open source project: Locking down dependencies

Cilium maintainers explain how they harden GitHub Actions and Go module dependencies with immutable references and trust checks during code review... read more ย 

Securing CI/CD for an open source project: Locking down dependencies
Link
@devopslinks shared a link, 1ย week ago
FAUN.dev()

GitHub pulls pin on npm's auto-run scripts

GitHub plans to makenpm installskip dependency lifecycle scripts by default in npm 12. That affects scripts such as: preinstall, install, postinstall, prepare The security gain is clear. The migration risk sits with packages that depend on install-time work, such as native module builds, generated f.. read more ย 

GitHub pulls pin on npm's auto-run scripts
Link
@devopslinks shared a link, 1ย week ago
FAUN.dev()

Grit: rewriting Git in Rust with agents

The creator of GitHub built Grit, a Rust reimplementation of Git as a library passing 99% of Git's test suite, paving the way for network efficient tools. But be cautious: while promising, Grit is not tested for production use and may still have bugs worth reporting for future improvements... read more ย 

Grit: rewriting Git in Rust with agents
Story
@laura_garcia shared a post, 1ย week, 1ย day ago
Software Developer, RELIANOID

RELIANOID at ๐—ฉ๐—ถ๐˜ƒ๐—ฎ๐—ง๐—ฒ๐—ฐ๐—ต ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ

๐Ÿš€ ๐—ฉ๐—ถ๐˜ƒ๐—ฎ๐—ง๐—ฒ๐—ฐ๐—ต ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ is bringing together the ๐—ด๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐—ถ๐—ป๐—ป๐—ผ๐˜ƒ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ecosystem! From startups and investors to enterprises and technology leaders, VivaTech 2026 is the place to explore the ๐˜ญ๐˜ข๐˜ต๐˜ฆ๐˜ด๐˜ต ๐˜ข๐˜ฅ๐˜ท๐˜ข๐˜ฏ๐˜ค๐˜ฆ๐˜ด ๐˜ช๐˜ฏ ๐˜ˆ๐˜, ๐˜ค๐˜บ๐˜ฃ๐˜ฆ๐˜ณ๐˜ด๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ, ๐˜ด๐˜ถ๐˜ด๐˜ต๐˜ข๐˜ช๐˜ฏ๐˜ข๐˜ฃ๐˜ช๐˜ญ๐˜ช๐˜ต๐˜บ, ๐˜ฅ๐˜ช๐˜จ๐˜ช๐˜ต๐˜ข๐˜ญ ๐˜ด๐˜ฐ๐˜ท๐˜ฆ๐˜ณ๐˜ฆ๐˜ช๐˜จ๐˜ฏ๐˜ต๐˜บ, ๐˜ข๐˜ฏ๐˜ฅ ๐˜ฆ๐˜ฎ๐˜ฆ๐˜ณ๐˜จ๐˜ช๐˜ฏ๐˜จ ๐˜ต๐˜ฆ๐˜ค๐˜ฉ๐˜ฏ๐˜ฐ๐˜ญ๐˜ฐ๐˜จ๐˜ช๐˜ฆ๐˜ด. ๐™๐™€๐™‡๐™„๐˜ผ๐™‰๐™Š๐™„๐˜ฟ is excite..

vivatech_paris_2026_june_relianoid
Story Trending
@vaibhavgupta shared a post, 1ย week, 1ย day ago

6+ Shadcn Register Sign Up Blocksย Examples

Next.js React tailwindcss Shadcn Space

The article showcases a collection of Shadcn/UI registration (sign-up) page blocks that developers can copy and customize for React/Next.js applications. The focus is on speeding up authentication UI development with modern, responsive, production-ready designs.

Best Shadcn Register blocks
Story Trending
@laura_garcia shared a post, 1ย week, 2ย days ago
Software Developer, RELIANOID

๐—œ๐—ฆ๐—ข/๐—œ๐—˜๐—– ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—ฆ๐˜๐—ฎ๐˜๐—ฒ๐—บ๐—ฒ๐—ป๐˜

๐Ÿ” Security and compliance are at the core of everything we do at RELIANOID. Our ๐—œ๐—ฆ๐—ข/๐—œ๐—˜๐—– ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ ๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—ฆ๐˜๐—ฎ๐˜๐—ฒ๐—บ๐—ฒ๐—ป๐˜ outlines how our organization and load balancing platform align with the security principles and controls of the ISO/IEC 27001:2022 framework. Learn more in our Security Compliance page..

Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.