Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.5k 547

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 652 137

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 894 164

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 166 51

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 227 49

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 39 21

Repositories

Showing 10 of 60 repositories
  • cosign Public

    Code signing and transparency for containers and binaries

    sigstore/cosign’s past year of commit activity
    Go 4,480 Apache-2.0 547 221 (1 issue needs help) 19 Updated Nov 5, 2024
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 123 54 51 5 Updated Nov 5, 2024
  • sigstore Public

    Common go library shared across sigstore services and clients

    sigstore/sigstore’s past year of commit activity
    Go 444 Apache-2.0 123 33 10 Updated Nov 5, 2024
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    sigstore/root-signing-staging’s past year of commit activity
    3 Apache-2.0 6 4 0 Updated Nov 5, 2024
  • sigstore-ruby Public

    Pure-ruby implementation of sigstore verification

    sigstore/sigstore-ruby’s past year of commit activity
    Ruby 6 Apache-2.0 1 1 1 Updated Nov 5, 2024
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 88 Apache-2.0 81 18 0 Updated Nov 5, 2024
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 25 Apache-2.0 26 19 1 Updated Nov 4, 2024
  • sigstore-java Public

    java clients for sigstore

    sigstore/sigstore-java’s past year of commit activity
    Java 39 Apache-2.0 21 22 10 Updated Nov 4, 2024
  • sigstore-conformance Public

    Conformance testing for Sigstore clients

    sigstore/sigstore-conformance’s past year of commit activity
    Python 7 10 18 1 Updated Nov 4, 2024
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 156 Apache-2.0 23 6 3 Updated Nov 4, 2024