Signing a model's files at build: a manifest lists every file with its cryptographic digest and a detached signature covers the manifest, so any changed file fails verification. The OpenSSF Model Signing specification uses the Sigstore bundle format and supports keyless signing, private PKI, self-signed certificates or bare keys 1. Serving verifies the signature before it loads a model.
- Developed in
- ch. 14, Reproducibility and linked versioning
ch. 05, Pattern: Model Artefact Integrity - Chapters
- ch. 05, Patterns · ch. 14, Development · ch. 15, Deployment
- Contrast with
- Build provenance (SLSA)
- Source
- 1 numbered reference, listed below
Where it is used
The term is not used under this name in running prose; the sections listed under "Developed in" treat it.
Related terms
Sources
- [1] "An Introduction to the OpenSSF Model Signing (OMS) Specification" (detached signature over a manifest of file hashes; Sigstore bundle format; PKI-agnostic: private PKI, self-signed certificates, bare keys, keyless Sigstore). OpenSSF. 2025-06-25. https://openssf.org/blog/2025/06/25/an-introduction-to-the-openssf-model-signing-oms-specification/ (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .