#sigstore
Tagged “sigstore”
2 articlesSupply chain security
Unsigned images meet an autonomous puller. What could go wrong.
The New Stack argues unsigned container images have always been a risk and become a bigger one when the puller is an AI agent with no human in the loop. The fix, image signing, has been on the shelf for years.
Aug 16, 2026 · Tomás VegaSecurity & supply chainCilium publishes its CI hardening playbook, gaps and all
The Cilium project's third post in its CI/CD hardening series walks through how it manages credentials and verifies what it ships, then lists the parts it has not fixed yet. The unusual move is publishing the unfinished work.
Jun 26, 2026 · Tomás Vega