Sigstore: Project to improve the open source supply chain

Sigstore: Project to improve the open source supply chain

Sigstore: Project to improve the open source supply chain

Today, we will talk about "Sigstore". One of many, of the free and open projects under the tutelage of the Linux Foundation.

"Sigstore" It is basically a project created to provide a non-profit public good service, to improve supply chain de open source software facilitating the adoption of software cryptographic signature backed by transparency registration technologies.

Automotive Grade Linux

"Sigstore", It's not the only one Linux Foundation project which we have talked about on previous occasions. Another of them has been Automotive Grade Linux, which we describe at the time as follows:

"Automotive Grade (Quality) Linux is an open source collaborative project that is bringing together automakers, vendors and technology companies to accelerate the development and adoption of a fully open software stack for the car of the future. With Linux at its core, AGL is developing an open platform from the ground up that can serve as the de facto industry standard to enable the rapid development of new features and technologies." Linux Foundation: Present at the Consumer Electronics Show 2020

Related article:
Linux Foundation: Present at the Consumer Electronics Show 2020

Related article:
Linux hits the road thanks to Automotive Grade Linux

Later, in future publications we will address other projects, but for those who wish to explore some of them by themselves, they can do so through the following link: Linux Foundation projects.

Sigstore: A project of the Linux Foundation

Sigstore: A project of the Linux Foundation

What is Sigstore?

According to his own Sigstore official website, the same is:

"A project created with the objective of providing a non-profit public good service to improve the open source software supply chain by facilitating the adoption of the software cryptographic signature, supported by transparency registration technologies. In addition, it tries to train software developers to securely sign software artifacts such as release files, container images, binaries, bill of materials manifests, and more."

In addition, this project seeks to ensure that:

"The signed materials are stored in a tamper-proof public record."

Why is Sigstore important?

This project, its tools and members, seeks to avoid «attacks on the software supply chain », such as, what happened with Solarwinds and others well known in recent times.

"Microsoft said the hackers compromised SolarWinds' Orion monitoring and management software, allowing them to impersonate any existing user and account in the organization, including highly privileged accounts. Russia is said to have exploited layers of the supply chain to access government agency systems."

Related article:
The SolarWinds hack could be much worse than expected

Be understood by «attack on the software supply chain » to the act by which, A hacker inserts malicious code into legitimate software to spread it everywhere.

Hence, free / open projects that are free and easy to implement, such as "Sigstore" they are more and more necessary in our days.

How to prevent attacks on the software supply chain?

Although, on other occasions, we have offered some useful information security advice, practical for everyone and at any time or situation, the following tips are directly focused on mitigating this type of attack as much as possible:

Related article:
Computer Security Tips for Everyone Anytime, Anywhere
  1. Maintain an inventory of all own and third-party software tools, both free and open, and proprietary and closed, that are used.
  2. Be aware of known and future vulnerabilities, of all applications and systems used, to apply as soon as possible the patches that are officially available.
  3. Stay informed about detected breaches or attacks carried out, to own and third-party software providers, to avoid unexpected surprises in these ways.
  4. Eliminate in the shortest possible time, those systems, services and protocols that may be redundant (unnecessary) or obsolete (unused).
  5. Plan and implement joint strategies and security requirements with your software providers, to minimize the IT risk from them and your own security processes.
  6. Run regular code audits. And keep updated security reviews and change control procedures, required for each component of the code created or used.
  7. Perform routine penetration tests to identify potential hazards on your computing platform.
  8. Implement IT security measures such as access controls and double factor authentication (2FA) to protect software development processes.
  9. Run security software with multiple layers of protection. Especially against intrusions, viruses and rasomwares, so common these days.
  10. Keep your backup or contingency plan up to date, in order to safely maintain the vital data of your applications, systems and activities (processes), and be able to recover any of them, in the shortest possible time.

More about Sigstore

More about Sigstore

Finally, the developers of "Sigstore" they explain a little the operation of this project in the following way:

"Sigstore leverages existing x509 PKI technologies and transparency registries. Users generate short-lived ephemeral key pairs using the sigstore client tools. The sigstore PKI service will then provide a signing certificate generated after a successful OpenID connect grant. All certificates are recorded in a certificate transparency registry and software signing materials are submitted to a signature transparency registry."

More about Sigstore

"Using transparency records introduces a root of trust in the user's OpenID account. Thus we can have guarantees that the claimed user was in control of the account of an identity service provider at the time of signing. Once the signing operation is complete, the keys can be discarded, eliminating any need for additional key management or the need for revocation or rotation."

For more information on "Sigstore" you can visit your official website on GitHub and Community (Group) public about Google.

Summary: Various publications

Your Order

We hope this "useful little post" about  «Sigstore», an interesting and useful project of the Linux Foundation, what is a transparency service and software signature public good and non-profit, created for improve supply chain open source software; is of great interest and utility, for the entire «Comunidad de Software Libre y Código Abierto» and of great contribution to the diffusion of the wonderful, gigantic and growing ecosystem of applications of «GNU/Linux».

For now, if you liked this publicación, Do not stop share it with others, on your favorite websites, channels, groups or communities of social networks or messaging systems, preferably free, open and / or more secure as TelegramSignalMastodon or another of Fediverse, preferably.

And remember to visit our home page at «FromLinux» to explore more news, as well as join our official channel of Telegram from DesdeLinuxWhile, for more information, you can visit any Online library Be OpenLibra y JedIT, to access and read digital books (PDFs) on this topic or others.

The content of the article adheres to our principles of editorial ethics. To report an error click here!.

Be the first to comment

Leave a Comment

Your email address will not be published. Required fields are marked with *



  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.