• You can sign commits to your code repository
  • You can sign from the build system to provide build provenance
  • You can sign production container images, blobs,or artifacts