The chainguard folks built sigstore :)

Yep yep, hence the ask, expected for containers, wondering if also for build from source.