Event language
UI language
Many have been flooded with news about “Supply Chain Security”. Why are end users, enterprises, and governments clamoring for it and why do I, as an open source contributor, need to care about it? Is this something that can be implemented easily? Enter sigstore, a project coming out of the OpenSSF (Open Source Security Foundation). The main goal of sigstore is to make signing artifacts, validating dependencies, and monitoring dependency releases, as easy as possible for developers. If we can lower the barrier of entry for open source projects to release software securely, we can make the world a better place.