Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Low-Code/No Code Artifact Signing

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Diamantis Kourkouzelis
Word Count
1,832
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs provides a private, seamless, and simple solution for artifact signing, serving as an alternative to Sigstore for organizations needing a private transparency log without the complexity of deploying and managing extensive infrastructure. Their keyless, identity-based artifact signing system leverages existing identity infrastructure, requiring no new infrastructure for deployment and maintenance, and integrates quickly into CI/CD pipelines and other environments. The system uses an identity-based or keyless approach, primarily relying on OpenID Connect (OIDC) authentication to issue short-lived certificates that bind ephemeral keys to OIDC identities. To ensure security and compliance, Endor Labs has decided against using tags for container images, opting instead for SHA256 digests to uniquely identify artifacts, thus eliminating the need for additional artifact registry access privileges. The infrastructure supports signature verification and revocation, ensuring signed artifacts maintain their integrity and can be verified against a trusted certificate authority. Endor Labs integrates seamlessly with tools like GitHub Actions, enhancing CI/CD security programs by offering visibility into pipeline tools, managing repository security posture, and providing artifact signing capabilities, all available in their free trial to explore their Software Supply Chain Security platform.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.