Kubernetes To Use Sigstore To Stop Supply Chain Attacks

May 5, 2022

Kubernetes will now add cryptographically signed signatures to protect users and organizations from supply chain attacks.

Access to the cryptographically signed signatures is via the Sigstore project created by the Linux Foundation.

Using sigstore certificates allows Kubernetes users to verify the authenticity and integrity of the distribution they are using.

According to founding Sigstore developer Dan Lorenc, the use of Sigstore certificates gives “users the ability to verify signatures and have greater confidence in the origin of each Kubernetes binary, source code bundle, and container image.”

Lorenc pointed out that Kubernetes’ adoption of Sigstore is part of its work on supply chain levels for Software Artifacts (SLSA). SLSA is a framework developed by Google for the internal protection of its software supply chain.

The Sigstore project is also aimed at Python developers. The aim of this project will be to release a new tool for signing Python packages as well as major package repositories such as Maven Central and RubyGems.

The sources for this piece include an article in ZDNet.

Top Stories

Related Articles

February 12, 2026 The Sun’s radiation has become an existential risk for spacecraft, and SpaceX is taking the fight underground, more...

February 11, 2026 In a sharp reversal that erased all gains made since Donald Trump’s 2025 election win, Bitcoin tumbled more...

February 10, 2026 Canada is about to make history in the race for clean energy by taking a homegrown fusion more...

January 30, 2026 Y Combinator has removed Canada from the list of countries where it will invest. The San Francisco–based more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn