Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the Sigstore ecosystem through data-driven insights about digital signing practices in this 18-minute conference talk. Learn how Sigstore provides tooling and services to simplify signing and verification while making signatures transparent and publicly auditable to detect malicious behavior. Discover the core components of Sigstore and understand how it enables secure digital signing for open source communities. Analyze trends in Sigstore adoption by examining data from Rekor, the public transparency log, to answer key questions about identity provider usage, signing patterns throughout the day, and the prevalence of short-lived certificates versus self-managed keys. Gain practical knowledge on how to access and leverage this transparency log data to conduct your own analysis of the Sigstore ecosystem and supply chain security signing practices.
Syllabus
Trends and Insights From the Sigstore Ecosystem - Eve Martin-Jones, Google
Taught by
OpenSSF