Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

PGP vs Sigstore - The Match at Maven Central

Devoxx via YouTube

Overview

Explore the world of software artifact signing in this informative conference talk comparing PGP and sigstore for Maven Central. Dive into the challenges of PGP key management for signing libraries and verifying dependencies to prevent software supply chain issues. Learn about the sigstore project, which promises easier keyless signatures, and its potential to revolutionize package registry security. Discover how sigstore works and its expected improvements for both signing and verification processes at Maven Central. Gain insights from Hervé Boutemy, a long-time Maven Committer and Apache Software Foundation member, as he shares his expertise on enhancing user experience in Maven.

Syllabus

PGP vs sigstore: the match at Maven Central by Hervé Boutemy

Taught by

Devoxx

Reviews

Start your review of PGP vs Sigstore - The Match at Maven Central

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.