Six questions on what software supply chain signing really checks: immutable artefact identity, what signatures prove, keyless workload identity, transparency logs, provenance, and why policy has to be narrower than signed somewhere in CI.
0 / 6
Why is signing `payments-api:stable` less trustworthy than signing `payments-api@sha256:...`?
Press 1 to 4 to pick an answer