Watch the recording
The player loads from YouTube when you choose to play.
Published by CNCF [Cloud Native Computing Foundation]. The source is authoritative for the recording title, date, and participants.
Questions to take into the discussion
- A platform team’s approach to retaining build evidence.
- The separate roles of Sigstore, Witness, and Archivista.
- How evidence can support a scoped technical control review.
Use these as an editorial guide while watching or exploring the topic. They are not quotations or a verified transcript of the session.
Apply the ideas to a current workflow
For an implementation, start with the shared documentation. CI/lock captures the work, Pushgate checks the push, and the platform manages gates and technical control evidence. Check the support matrix for the release and environment you intend to use.
A signed statement can establish attribution and detect alteration under a configured trust model. It does not establish that the producer reported honestly or that a whole compliance framework is satisfied. The trust architecture explains those boundaries.