Skip to main content
This information is for Chronosphere Telemetry Pipeline, which is a standalone product separate from Chronosphere Observability Platform.
Part of security is ensuring that the software supply chain is as secure as possible. As part of secure development practices, Chronosphere provides the following keys you can use to verify the signatures of Chronosphere Telemetry Pipeline software.

Cosign keys

Cosign is a tool to sign, verify, and store software artifacts in an OCI (Open Container Initiative) registry. You can use a tool like the Kubernetes Policy Controller to verify supply chain metadata from Cosign. The Chronosphere Telemetry Pipeline public Cosign key is available here.

GPG keys

GPG (GNU privacy guard) is an open source implementation of the OpenPGP protocol. You can verify the signature of Telemetry Pipeline packages to ensure that the signature is valid.

Artifacts released on or after 2026-03-24

Use the following GPG key to verify Telemetry Pipeline software packages released on or after 2026-03-24:
When you verify the Telemetry Pipeline public GPG key, the information output to your terminal should match this key fingerprint:

Artifacts released before 2026-03-24

Use the following GPG key to verify Telemetry Pipeline software packages released before 2026-03-24:
When you verify the Telemetry Pipeline public GPG key, the information output to your terminal should match this key fingerprint:

SBOM and other reports

Software bill of materials (SBOMs) are generated for each release, along with Common Vulnerabilities and Exposures (CVE) reports at the time of release. To access these materials, contact Chronosphere support.