A new Linux Foundation open source signing tool could make secure software supply chains universal

sigstore could eliminate the headaches associated with current software signing technology through public ledgers.
Source: techrepublic.com/rssfeeds/topic/open-source/