GitLab Secrets Manager
How to secure your software build pipeline using code signing

How to secure your software build pipeline using code signing

8/30/2021 · Eddie Glenn

What this post added

This post details a partnership between Venafi and GitLab to enhance software build pipeline security through code signing. It explains the importance of signing artifacts early and often to prevent supply chain attacks, the challenges of managing PKI and keys, and how the Venafi CodeSign Protect solution integrates with GitLab to simplify the code signing process for developers. The post also highlights the 'shift-left' security approach and provides resources for further learning.

Read the original post ↗