Low-Code/No Code Artifact Signing
Blog post from Endor Labs
Endor Labs provides a private, seamless, and simple solution for artifact signing, serving as an alternative to Sigstore for organizations needing a private transparency log without the complexity of deploying and managing extensive infrastructure. Their keyless, identity-based artifact signing system leverages existing identity infrastructure, requiring no new infrastructure for deployment and maintenance, and integrates quickly into CI/CD pipelines and other environments. The system uses an identity-based or keyless approach, primarily relying on OpenID Connect (OIDC) authentication to issue short-lived certificates that bind ephemeral keys to OIDC identities. To ensure security and compliance, Endor Labs has decided against using tags for container images, opting instead for SHA256 digests to uniquely identify artifacts, thus eliminating the need for additional artifact registry access privileges. The infrastructure supports signature verification and revocation, ensuring signed artifacts maintain their integrity and can be verified against a trusted certificate authority. Endor Labs integrates seamlessly with tools like GitHub Actions, enhancing CI/CD security programs by offering visibility into pipeline tools, managing repository security posture, and providing artifact signing capabilities, all available in their free trial to explore their Software Supply Chain Security platform.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.