Sigstore: Software Signing for Everybody
Zachary Newman, John Speed Meyers, Santiago Torres-Arias
2022Year
35Citations
18Top-tier citations
Abstract
Software supply chain compromises are on the rise. From the effects of XCodeGhost to SolarWinds, hackers have identified that targeting weak points in the supply chain allows them to compromise high-value targets such as U.S. government agencies and corporate targets such as Google and Microsoft. Software signing, a promising mitigation for many of these attacks, has seen limited adoption in open-source and enterprise ecosystems.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers18
- Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing FactorsTaylor R. Schorlemmer, Kelechi G. Kalu, Luke Chigges, Kyung Myung Ko et al.S&P 2024 · 17 citations
- Speranza: Usable, Privacy-friendly Software SigningKelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen R. SollinsCCS 2023 · 5 citations
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines et al.ICSE 2026 · 5 citations
- Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of SigstoreKelechi G. Kalu, Sofia Okorafor, Tanmay Singla, Sophie Chen et al.USENIX Security 2026 · 3 citations
- : Mitigating Software Supply Chain Vulnerabilities via Zero-Trust DependenciesPaschal C. Amusuo, Kyle A. Robinson, Tanmay Singla, Huiyun Peng et al.ICSE 2025 · 2 citations
Related papers
- An Industry Interview Study of Software Signing for Supply Chain SecurityKelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias et al.USENIX Security 2025
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl et al.ICSE 2025 · 1 citation
- Where is it? Tracing the Vulnerability-relevant Files from Vulnerability ReportsJiamou Sun, Jieshan Chen, Zhenchang Xing, Qinghua Lu et al.ICSE 2024 · 8 citations
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
- An Empirical Study of Observability Limits in Advanced Software Supply Chain AttacksZhuoran Tan, Wenbo Guo, Jiewen Luo, Taylor Brierley et al.CCS 2026 · 3 citations
