Luke Hinds is a founder and globally recognized leader in open source, cybersecurity and AI, best known as the creator of Sigstore — the supply‑chain security stack adopted by Google, Nvidia, GitHub and JPMC. He blends hands‑on backend and security engineering (OIDC, algorithm‑agile key management, certificate transparency and transparency log work in Fulcio and Rekor) with program‑level stewardship, having run Kubernetes vulnerability response at CNCF and served on OpenSSF and Confidential Computing boards. Luke co‑founded stacklok, leads Red Dot Rocket to advise on safe AI/agents and supply‑chain security, and is currently incubating a stealth startup focused on AI agents. His open-source contributions also span trust at the edge and IoT (Keylime) and practical tooling that moves cryptography and DevSecOps into production. Based in Bristol, he pairs deep technical rigor with endurance‑athlete resilience, a combination that fuels long‑term, community‑centered project leadership.
A CNCF Project to Bootstrap & Maintain Trust on the Edge / Cloud and IoT
Role in this project:
Back-end & DevOps Engineer
Contributions:22 releases, 53 reviews, 242 commits in 3 years 7 months
Contributions summary:Luke contributed significantly to enhancing the Keylime project by adding support for various RHEL family distributions, including Red Hat, CentOS, and Fedora, demonstrating proficiency in shell scripting and system administration. They updated demo and whitelist scripts, ensuring cross-platform compatibility across different package managers. Further contributions involved implementing pip requirements for testing and integrating CA provider checks with keylime.conf, indicating expertise in build processes, configuration management, and potentially, security aspects related to CA implementations.
Common go library shared across sigstore services and clients
Role in this project:
Backend & Security Engineer
Contributions:78 reviews, 68 commits, 96 PRs in 1 year 2 months
Contributions summary:Luke primarily contributed to the backend functionality of the sigstore project, focusing on certificate generation and key management. They implemented key generation with algorithm agility and integrated OpenID Connect (OIDC) for authentication. Furthermore, the user's work included file type checking and integration with Rekor, the transparency log, involving the signing and submission of artifacts to a secure log.
cosigngolangshared-librarysecuritysupply-chain
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.