Chainguard Images Sigstore bundle by Chainguard is a collection of 17 images compatible with official helm charts, providing enterprises a secure way to run Sigstore in their environments with low CVEs, a minimal footprint, and Software Bills of Material (SBOMs). It includes everything needed to run a Sigstore stack, such as Fulcio, Rekor, Trillian, CT Log, Redis, Cosign, Timestamp Authority, and the necessary configuration utilities. Using Chainguard Images for Sigstore makes software signing accessible for organizations seeking a private, on-prem solution to enhance their software supply chain security. It is already utilized by Hewlett Packard Enterprise (HPE). Sigstore has evolved from a small project to a critical infrastructure for securing open source software and is now integrated with five major package manager ecosystems: Python, NPM, Maven Central, OCI, and Homebrew. Chainguard Images Sigstore bundle provides organizations with a supported Sigstore stack optimized for enterprise deployments, ensuring control and ownership for safe and secure operation to meet compliance requirements. It offers FIPS-compliant versions of the Chainguard Images for Sigstore. Signing and verifying software is a critical component of a secure supply chain, as emphasized by the Cybersecurity and Infrastructure Security Agency (CISA). Chainguard’s Sigstore Images are available for free to help meet these compliance requirements and improve the container image landscape with a secure-by-default design.