This is the repository for the Sigstore Public Good Operations Special Interest Group (SIG).
We are a group of volunteer engineers from various companies collaborating to operate and maintain the Sigstore Public Good instance.
The public good instance is becoming a crucial piece of infrastructure for the open source software ecosystem. Multiple package managers (such as npm) and high-profile projects (like Kubernetes) use this infrastructure to produce signed builds for distribution worldwide.
The sig-ops group primarily focuses on running the public good infrastructure. While not the primary focus, our work utilizes or overlaps with the following projects:
(You'll need to join sigstore-dev@googlegroups.com for access to many of these (to prevent spam).)
Meetings. Check the sigstore community calendar for meeting invitations/times (see community repository for more).
- Sigstore Infra meeting (weekly, notes)
Slack. We communicate on Slack. Our primary channel is #sigstore-infra
. Other channels that might be of interest include: #helm-charts
and #private-sigstore-users
.
Should you discover any security issues, please refer to Sigstore's security process