Don't Panic: A Playbook for Handling Account Compromise with Sigstore
blog.sigstore.dev
blog.sigstore.dev
Quick note, your link to your securities policies under FAQ is returning a 404.
> What security checks do you use internally?
> We’ve adopted a security disclosures and response policy to make sure we can responsibly handle critical issues. We have an initial Security Response Committee, who for each vulnerability reported will coordinate to create the fix and release, and keep the committee looped in. The policy in full is here: https://github.com/sigstore/community/blob/main/SECURITY.md