Vigilance vs Sigstore and SLSA
Sigstore and SLSA. Signs a release and records how it was built, so you can prove where it came from. Vigilance finds the update that gained a hidden power, before you install it.
The Catch Sigstore and SLSA Cannot Make
Sigstore proves a release came from the build you expect. A signed release can still carry a hidden power. Vigilance does not check the signature. It reads the code. It compares the version you trust with the version you install. It reports any file that can suddenly do more.
A real one: xz Utils, 2024
xz is a compression library on almost every Linux server. In release 5.6.1, a hidden backdoor shipped inside liblzma. It can intercept a remote login. The release was signed by its own maintainer. The signature was valid, so a signature check passes it. One command sees it:
vigi diff --old ./xz-5.4.6 --new ./xz-5.6.1
HEADS UP. 1 file changed. liblzma can now run hidden code during a remote login.
Run both. Sigstore proves who signed the release. Vigilance reads what the signed release actually does. See them side by side below.
Side by Side
| Question | Sigstore and SLSA | Vigilance |
|---|---|---|
| Proves who built a release | Yes | No |
| Proves nobody swapped it in transit | Yes | No |
| Tells you what changed inside the release | No | Yes |
| Helps when the attacker is inside the build | No | Yes |
| Covers software that ships with no signature | No | Yes |
| Needs a key or an online service | Yes | Pro: a license file, no online service. Free: online. |
Which One Do You Need?
Use both. A signature proves who made the file. It does not tell you what changed inside the file. The biggest recent supply chain attacks, SolarWinds and 3CX, shipped correctly signed.
Known Risk versus New Risk
A bug or a bad package someone already reported, with a name and a number. Most tools work here.
A file that gained a capability it never had, that no report covers yet. Vigilance works here.
Common Questions
Is Vigilance a Sigstore and SLSA Alternative?
Yes, for one job. Vigilance shows the file that gained a new capability, on your own machine. Many teams run it next to Sigstore and SLSA.
What Does Vigilance Do That Sigstore and SLSA Does Not?
Vigilance can spot a file that can do more than the version before, and on Pro run with no internet at all.
What Does Sigstore and SLSA Do That Vigilance Does Not?
Sigstore and SLSA proves where a release came from and how it was built. Vigilance does not sign anything.
Does Vigilance Need the Internet or a Cloud Account?
The Free plan runs online. Pro runs fully offline, with no cloud account.
Try It on Your Own Software.
Show it the version you run today and the one you are about to install.
Talk to Us
A question, a pilot, or a bigger fleet? Send a note. It reaches a person.