Sigstore - Software Artifact Signing and Verification
Private Deployment

Sigstore - Software Artifact Signing and Verification SIGSTORE-4: Private Deployment, Long-Lived Migration, Regulated Environments

Per Sigstore: private deployment + migration. Requirements include (a) Private Sigstore Deployment for Regulated Environments + (b) Long-Lived Key Migration and Sunset + (c) operate enterprise-internal Sigstore.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.