This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
product separate from Palo Alto Networks Cortex XCOR.
Part of security is ensuring that the software supply chain is as secure as possible.
As part of secure development practices, Palo Alto Networks Telemetry Pipeline provides the
following keys you
can use to verify the signatures of Palo Alto Networks Telemetry Pipeline software.
Cosign keys
Cosign
is a tool to sign, verify, and store software artifacts in an OCI (Open Container
Initiative) registry. You can use a tool like the
Kubernetes Policy Controller
to verify supply chain metadata from Cosign.
The Palo Alto Networks Telemetry Pipeline public Cosign key is available
here.
GPG keys
GPG (GNU privacy guard) is an open source implementation of the OpenPGP protocol.
You can verify the signature of Palo Alto Networks Telemetry Pipeline packages to ensure that the
signature is valid.
Artifacts released on or after 2026-03-24
Use the following GPG key to verify Palo Alto Networks Telemetry Pipeline software packages released
on or after 2026-03-24:
When you verify the Palo Alto Networks Telemetry Pipeline public GPG key,
the information output to your
terminal should match this key fingerprint:
Artifacts released before 2026-03-24
Use the following GPG key to verify Palo Alto Networks Telemetry Pipeline software packages released
before 2026-03-24:
When you verify the Palo Alto Networks Telemetry Pipeline public GPG key,
the information output to your
terminal should match this key fingerprint:
SBOM and other reports
Software bill of materials (SBOMs) are generated for each release, along with Common
Vulnerabilities and Exposures (CVE) reports at the time of release. To access these
materials, contact Cortex XCOR Support.