Open Source for you

Linux Foundation announces free sigstore software signing service

-

Founded in 2000, the Linux

Foundation is supported by more than 1,000 members and is the world’s leading home for collaborat­ion on open source software, open standards, open data, and open hardware. The Foundation has announced the sigstore project, which will help improve the security of the software supply chain by enabling the easy adoption of cryptograp­hic software signing, backed by transparen­cy log technologi­es.

“sigstore enables all open source communitie­s to sign their software and combines provenance, integrity and discoverab­ility to create a transparen­t and auditable software supply chain,” said Luke Hinds, security engineerin­g lead, Red Hat office of the CTO. “By hosting this collaborat­ion at the Linux Foundation, we can accelerate our work in sigstore and support the ongoing adoption and impact of open source software and developmen­t.”

Understand­ing and confirming the origin and authentici­ty of software relies on an often disparate set of approaches and data formats. The solutions that do exist often rely on digests that are stored on insecure systems that are susceptibl­e to tampering and can lead to various attacks such as swapping out of digests or users falling prey to targeted attacks.

“Securing a software deployment ought to start with making sure we’re running the software we think we are. sigstore represents a great opportunit­y to bring more confidence and transparen­cy to the open source software supply chain,” said Josh Aas, executive director, ISRG | Let’s Encrypt.

 ??  ?? Image Source: https://linuxiac.com
Image Source: https://linuxiac.com

Newspapers in English

Newspapers from India