Enhancing artifact security with GitHub Artifact Attestations

Day 1 | 18:30 | 00:30 | UB4.132 | Fredrik Skogman


Note: I'm reworking this at the moment, some things won't work.

The stream isn't available yet! Check back at 18:30.

In the evolving landscape of software development, ensuring the integrity of build artifacts like container images is crucial. GitHub Artifact Attestations is an artifact signing solution and PKI built on open source software like TUF and Sigstore. In this talk, I'll discuss and demonstrate how to use Artifact Attestations to generate signed SLSA attestations, and verifying their origin and authenticity. By the end of this session, you'll have a good understanding of how open source tools like Sigstore, in-toto, SLSA and TUF can collectively strengthen the security of the software supply chain.