Signing Software Artifacts with Sigstore Cosign
This tutorial on deploying Sigstore (Cosign, Rekor, Fulcio) for container and binary integrity on Ubuntu covers keyless compared with key-based models, Fulcio's OIDC trust, Rekor transparency usage, and verification policy design.