Why Signing Both JAR and Container Image Matters for Pipeline Security

A software team building a CI/CD pipeline discovered that signing only the JAR artifact left a critical gap, since the container image — not the JAR — is what actually runs in production. To close this gap, they extended artifact signing to cover the container image as well, making each handoff in the build chain independently verifiable. The signing key is strictly restricted to the pipeline runner's role, ensuring no developer or local build can produce a valid signed artifact. The team consistently rejects requests for manual signing workarounds, arguing that allowing human signatures would reduce every signature's guarantee from 'came from the pipeline' to 'probably came from the pipeline'. Their conclusion is that artifact signing is a narrower security property than often claimed, and its value depends entirely on who can access the signing key and schedule jobs on the build runner.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in