From 1ae679ba832c111353a478bfe49e91df041ed519 Mon Sep 17 00:00:00 2001 From: Simon Mayer Date: Tue, 2 Sep 2025 08:35:25 +0200 Subject: [PATCH] Add information regarding artifact signing --- docs/docs/06-For CISOs/artifacts-signing.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/docs/docs/06-For CISOs/artifacts-signing.md b/docs/docs/06-For CISOs/artifacts-signing.md index 93d18dc..6d3afa6 100644 --- a/docs/docs/06-For CISOs/artifacts-signing.md +++ b/docs/docs/06-For CISOs/artifacts-signing.md @@ -1,7 +1,10 @@ --- slug: /artifact-signing title: Artifact Signing -draft: true --- # Artifact Signing + +To increase trust and integrity, metal-stack introduces artifact signing for its released components. + +The release vector is now published as an OCI artifact and signed using [cosign](https://github.com/sigstore/cosign). While this feature is currently available as a preview, our long-term goal is to extend signing to all metal-stack container images as well, ensuring that users can always verify the authenticity of the artifacts they consume. \ No newline at end of file