← All audiences

Open Source Maintainer

Sign releases without managing keys.

Use cases for this audience

CI/CD Signing

Sign build artifacts at release time using threshold keys held outside CI. Compromising CI does not compromise the signing key.

GitHub Release Signing

Sign GitHub release artifacts keylessly using OIDC. No long-lived signing key to manage or compromise.

Artifact Provenance

Generate SLSA-compatible provenance attestations for build artifacts, anchored to a transparency log.

OIDC-Based Keyless Signing

Use GitHub, Google, GitLab, Azure AD, or Okta as the identity provider for short-lived signing certificates.

Supply Chain Attestation

Produce verifiable attestations linking artifacts to their source, build, and signing ceremony.