Hacker News new | past | comments | ask | show | jobs | submit
https://www.sigstore.dev/

The emerging standard for verifying artifacts, e.g. in container image signing, npm, maven, etc

https://blog.sigstore.dev/npm-public-beta/ https://www.sonatype.com/blog/maven-central-and-sigstore

Emerging standard = not yet the standard
Nobody said it was. The point is that it's better.