Sigstore and SLSA: Verifying Who Built an Artifact with Which Process
Sigstore provides identity-bound signing, short-lived certificates, and transparency logs; SLSA describes trustworthy build provenance. They protect only when admission verifies identity, issuer, digest, and build expectations.