Chapter 1. Introduction


Red Hat’s Trusted Artifact Signer (RHTAS) service enhances software supply chain security by simplifying cryptographic signing and verifying of software artifacts, such as container images, binaries, and Git commits. Trusted Artifact Signer provides a production ready deployment of the SecureSign community project.

The Trusted Artifact Signer software Release Notes documents new features and enhancements, bug fixes, and known issues for the latest version, 1.4. We add the newest items to the top in each chapter, as we build upon the official release notes over the lifecycle of the major, and minor releases.

New for this release
  • Generally Available : The ability to configure the RHTAS services for high-availability environments.
  • Generally Available : Implementation of the Sigstore Policy Controller admission controller for Red Hat OpenShift Container Platform.
  • Generally Available : Support for using a PostgreSQL database for Trillian.
  • Technology Preview : Signing and verifying AI/ML models.
  • Technology Preview : RHTAS Console, a web-based user interface where users can search the transparency log, and view signing events.
  • Technology Preview : Key Management Service (KMS) support for managing Rekor signing keys.
  • New cosign version 3.0.4, helping to streamline the initialization process.
  • Various Conforma improvements and fixes.
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat Documentation

Legal Notice

Theme

© 2026 Red Hat
Back to top