| name | implementing-code-signing-for-artifacts |
| description | Use when this skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines. |
| domain | cybersecurity |
| tags | ["devsecops","cicd","code-signing","supply-chain","sigstore","secure-sdlc"] |
| subdomain | devsecops |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","GV.SC-07","ID.IM-04","PR.PS-04"] |
Implementing Code Signing For Artifacts
Overview
Cybersecurity skill for implementing code signing for artifacts. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing code signing for artifacts"
-
"This skill covers implementing code signing for build artifacts to ensure integr"
-
When establishing artifact integrity verification to prevent supply chain tampering
-
When compliance requires cryptographic proof that build artifacts are authentic and unmodified
-
When distributing software to customers who need to verify publisher identity
-
When implementing zero-trust deployment pipelines that reject unsigned artifacts
-
When meeting SLSA Level 2+ requirements for provenance and integrity
Do not use for encrypting artifacts (signing provides integrity, not confidentiality), for container image signing specifically (use cosign), or for source code authentication (use commit signing).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- GPG key pair for traditional signing or Sigstore account for keyless signing
- Code signing certificate from a Certificate Authority for public distribution
- CI/CD pipeline with access to signing keys or identity provider
- Verification infrastructure in deployment pipelines
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}