Hacker News with Generative AI: Code Signing

A brief history of code signing at Mozilla (hearsum.ca)
Shipping large software to end-user devices is a complicated process. Shipping large software securely to end-user devices is even more complicated. Signing the things that ship to end-user devices is one of those complications, and it gets even more complicated when you sign thousands of artifacts per day.
Sigstore: Making sure your software is what it claims to be (sigstore.dev)
Loading...
The Challenges of Building a Sigstore Implementation from Scratch [video] (youtube.com)
An open-source implementation of Apple code signing and notarization (2022) (gregoryszorc.com)