• Software signing helps with an important (but not exhaustive) class of supply chain attacks.
  • Even then, verifying the wrong way can render your signing scheme useless: just “signing” isn’t sufficient.
  • It’s tricky to create the right verification policy, which tells you how to verify, because of the potential of subtle attacks; The Update Framework (TUF) is a great way to build smart-but-flexible verification policies for your needs.
  • TUF and Sigstore are a match made in heaven: easy signing, with rigorous verification policies.