AI Snips
Chapters
Transcript
Episode notes
MiniKube Security Scare
- Dan Lorenc's work on MiniKube made him realize the security risks of users running binaries from unknown sources.
- This led him to focus on supply chain security, including projects like TektonCD and Sigstore.
Securing Open Source
- Improve security practices and make it easier for people to do the right thing.
- Automate the capture of verifiable supply chain metadata and provide easy code signing.
Sigstore Key Ceremony
- Sigstore's root certificate signing event involves five keyholders with individual hardware tokens. These tokens are used to sign everything and distributed to ensure resiliency, like Horcruxes.


