Sign OCI containers & other artifacts using Sigstore Cosign & CircleCI OIDC tokens
Sigstore’s Fulcio certificate authority now recognizes CircleCI’s OIDC tokens. This means you can sign container images and other artifacts directly from your CircleCI pipelines—without managing long-lived signing keys.