← Back to security

Supply Chain Signing

6 questions · ~6 min · intermediate

Six questions on what software supply chain signing really checks: immutable artefact identity, what signatures prove, keyless workload identity, transparency logs, provenance, and why policy has to be narrower than signed somewhere in CI.

0 / 6

Why is signing `payments-api:stable` less trustworthy than signing `payments-api@sha256:...`?

Press 1 to 4 to pick an answer