Mission Stacklok’s mission is to make it easier to securely develop software. We help developers better understand how their practices and choices impact the security of the software they produce, and we enable companies to implement and insist on practices that lead to safer software delivery and better production security posture.
Description After co-founding the open-source system Kubernetes at Google in 2015 and working to support enterprises with its adoption while at Heptio and VMware, Stacklok CEO Craig McLuckie began turning his attention to the open-source supply chain ecosystem. Executive Order 14028 had come out, establishing stricter standards on supply chain security—but the tools to help developers and open source communities build safer software were still nascent.
One promising tool was Sigstore, founded by Stacklok CTO Luke Hinds in 2020 during his tenure as a distinguished engineer at Red Hat. Sigstore, an open source project, makes it dramatically easier to sign and verify software artifacts, giving downstream consumers confidence in where their software is coming from.
Luke and Craig saw an opportunity to build on Sigstore’s achievements. They founded Stacklok in May 2023 to provide more tooling and support for developers and open source communities to more easily keep their software secure and manage external dependency risk.