You are viewing the 2025 edition of FOSDEM. Click here to view the 2026 edition
Enhancing artifact security with GitHub Artifact Attestations
UB4.132 | Day 1 | 18:30 - 19:00 | Speakers: Fredrik Skogman
Enhancing artifact security with GitHub Artifact Attestations
Abstract
In the evolving landscape of software development, ensuring the integrity of build artifacts like container images is crucial. GitHub Artifact Attestations is an artifact signing solution and PKI built on open source software like TUF and Sigstore. In this talk, I'll discuss and demonstrate how to use Artifact Attestations to generate signed SLSA attestations, and verifying their origin and authenticity. By the end of this session, you'll have a good understanding of how open source tools like Sigstore, in-toto, SLSA and TUF can collectively strengthen the security of the software supply chain.
Attachments
Speakers
Fredrik Skogman
Links
External Links
Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.
