Hacker News new | past | comments | ask | show | jobs | submit
What are these "much better alternatives"?
https://www.sigstore.dev/

The emerging standard for verifying artifacts, e.g. in container image signing, npm, maven, etc

https://blog.sigstore.dev/npm-public-beta/ https://www.sonatype.com/blog/maven-central-and-sigstore

Emerging standard = not yet the standard
loading story #41876472