Trendora

Sigstore cosign

Assess

Tools

A code-signing tool used to sign kernel artifacts and verify their integrity.

Why it's here

Placed in Assess: 1 article(s) of evidence from 1 source(s), led by security coverage, with 0 in the last 30 days. Confidence 24%. Low accumulated evidence, so it defaults conservatively pending more signal.

Evidence (1)

  • 7Hugging Face Blog·7/6/2026security
    Hugging Face overhauls Kernels with new repo type and security features

    Hugging Face announced major updates to its Kernels project, including a new Hub repository type for kernels and improved support for discovering supported accelerators, operating systems, and backend versions. The release also adds stronger security measures such as trusted publishers, default restrictions on loading untrusted kernels, and code signing with Sigstore cosign. The team says the project has been substantially redesigned and more updates are coming.