Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Artifact Signing

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Security
Word Count
212
Company Posts That Month
47
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs offers a solution for artifact signing that enhances security in the CI pipeline by cryptographically signing container images, binaries, and other build artifacts, and verifying them at deployment to prevent unsigned or tampered code from running. This approach is based on principles similar to Sigstore, ensuring privacy through the use of existing SSO identities, single-use ephemeral certificates, and a tamper-resistant signature log, tailored to each tenant's needs. The brief coincides with Endor Labs' involvement in BlackHat 2026 in Las Vegas, highlighting their focus on innovative security solutions. Additionally, Endor Labs addresses potential security threats in GitHub action workflows by identifying patterns that suggest PWN request threats, while exploring the use of AI in achieving a shift-left strategy, increasing release velocity, and building developer trust.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.