DevOps Paradox cover image

DOP 277: Making Security Tooling Easy for Developers

DevOps Paradox

00:00

Understanding Offline Bundles and Trust Mechanisms in SigStore

This chapter explores the technicalities of SigStore's offline bundle and its dependence on a root certificate authority for verifying signed artifacts and containers. It highlights the role of transparency and community engagement in the certification process, particularly the annual renewal of root certificates.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app