Trusty is a free-to-use web app that provides data and scoring on the supply chain risk for open source packages.
We traveled to beautiful Bilbao, Spain, on September 18, to attend OpenSSF Day Europe and talk open source security.
At OpenSSF Day, Stacklok Principal Engineer Evan Anderson led a session to give attendees a tour of Sigstore's "public good instance."
This public-good instance is a community-operated service for developers, run and managed by OpenSSF. Stacklok engineers like Evan, along with engineers from several member companies, volunteer their time to participate in the on-call rotation and maintain the public good instance.
Read more about how Sigstore's public good instance operates on OpenSSF's blog.
Photo credit: Unsplash