Linux Foundation unveils Sigstore — a Let’s Encrypt for code signing

The Linux Foundation, Red Hat, Google, and Purdue have unveiled the free ‘sigstore’ service that lets developers code-sign and verify open source software to prevent supply-chain attacks. […]