Code Signing is a cryptographic practice in which software publishers digitally sign executables, scripts, container images, and other software artefacts using a private key, enabling recipients to verify the artefact’s authenticity and integrity through the corresponding public key certificate. Implemented via asymmetric cryptography and X.509 certificate chains anchored to trusted Certificate Authorities or transparency logs, code signing is a fundamental control in software supply chain security, preventing the distribution of tampered or malicious software. Modern approaches include keyless signing via short-lived certificates and cryptographic transparency logs.

Content

  • Code signing emerged in the mid-1990s alongside the commercial internet, as Microsoft’s Authenticode (1996) and Netscape’s Object Signing enabled browser-downloaded executables to carry publisher certificates. Apple adopted code signing requirements for macOS applications in 2011 (Gatekeeper) and enforced it for all Mac App Store submissions. iOS mandated code signing from launch (2007), making every installed app cryptographically traceable to a registered Apple Developer account. These platform-level enforcements established code signing as an operational baseline.
  • Technically, code signing for modern software artefacts extends beyond simple binary signing. Container image signing (Notary v1 with TUF, Notary v2/OCI, Cosign) signs OCI manifests stored in container registries. The Sigstore project (2021, supported by Google, Red Hat, Purdue University) introduced keyless signing using ephemeral keys bound to OIDC identity tokens (GitHub Actions, GitLab CI identities), with all signatures published to the Rekor append-only transparency log. This removes the burden of long-lived key management whilst providing transparency log-based non-repudiation.
  • Enterprise software supply chains typically require code signing at multiple stages: source code commits (GPG/SSH-signed Git commits), build artefacts (signed JARs, signed npm packages, signed Python wheels), container images (Cosign or Notary), and Helm charts. The SLSA framework (now at SLSA v1.0) defines provenance levels from L1 (scripted build) to L3 (verified, non-falsifiable build) where L2+ requires signed provenance attestations. Tools such as in-toto (attestation framework), SPDX (software bill of materials), and CycloneDX integrate with code signing to provide comprehensive artefact provenance.
  • By 2024–2025, code signing has become a regulatory expectation in sectors subject to the EU Cyber Resilience Act, US Executive Order 14028 on Improving the Nation’s Cybersecurity, and CISA guidance on software supply chain security. Sigstore has achieved broad adoption with over 1 million container image signatures and integration into major package registries (npm, PyPI, Maven Central, crates.io). The convergence of software bills of materials, Provenance Tracking, and code signing is creating an end-to-end Supply Chain Traceability capability for software that mirrors what physical supply chains have achieved through barcode and RFID traceability systems.