Watch the recording

The player loads from YouTube when you choose to play.

Open the recording at its source ↗

Published by CNCF [Cloud Native Computing Foundation]. The source is authoritative for the recording title, date, and participants.

Questions to take into the discussion

  • A platform team’s approach to retaining build evidence.
  • The separate roles of Sigstore, Witness, and Archivista.
  • How evidence can support a scoped technical control review.

Use these as an editorial guide while watching or exploring the topic. They are not quotations or a verified transcript of the session.

Apply the ideas to a current workflow

For an implementation, start with the shared documentation. CI/lock captures the work, Pushgate checks the push, and the platform manages gates and technical control evidence. Check the support matrix for the release and environment you intend to use.

A signed statement can establish attribution and detect alteration under a configured trust model. It does not establish that the producer reported honestly or that a whole compliance framework is satisfied. The trust architecture explains those boundaries.