Skip to main content
This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone product separate from Palo Alto Networks Cortex XCOR.
Part of security is ensuring that the software supply chain is as secure as possible. As part of secure development practices, Palo Alto Networks Telemetry Pipeline provides the following keys you can use to verify the signatures of Palo Alto Networks Telemetry Pipeline software.

Cosign keys

Cosign is a tool to sign, verify, and store software artifacts in an OCI (Open Container Initiative) registry. You can use a tool like the Kubernetes Policy Controller to verify supply chain metadata from Cosign. The Palo Alto Networks Telemetry Pipeline public Cosign key is available here.

GPG keys

GPG (GNU privacy guard) is an open source implementation of the OpenPGP protocol. You can verify the signature of Palo Alto Networks Telemetry Pipeline packages to ensure that the signature is valid.

Artifacts released on or after 2026-03-24

Use the following GPG key to verify Palo Alto Networks Telemetry Pipeline software packages released on or after 2026-03-24:
When you verify the Palo Alto Networks Telemetry Pipeline public GPG key, the information output to your terminal should match this key fingerprint:

Artifacts released before 2026-03-24

Use the following GPG key to verify Palo Alto Networks Telemetry Pipeline software packages released before 2026-03-24:
When you verify the Palo Alto Networks Telemetry Pipeline public GPG key, the information output to your terminal should match this key fingerprint:

SBOM and other reports

Software bill of materials (SBOMs) are generated for each release, along with Common Vulnerabilities and Exposures (CVE) reports at the time of release. To access these materials, contact Cortex XCOR Support.