Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.7k 558

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 674 142

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 930 168

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 186 56

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 251 51

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 50 21

Repositories

Showing 10 of 60 repositories
  • cosign-installer Public

    Cosign Github Action

    sigstore/cosign-installer’s past year of commit activity
    136 Apache-2.0 43 0 0 Updated Feb 5, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 96 Apache-2.0 83 17 2 Updated Feb 5, 2025
  • rekor Public

    Software Supply Chain Transparency Log

    sigstore/rekor’s past year of commit activity
    Go 930 Apache-2.0 168 77 8 Updated Feb 5, 2025
  • fulcio Public

    Sigstore OIDC PKI

    sigstore/fulcio’s past year of commit activity
    Go 674 Apache-2.0 142 49 (1 issue needs help) 10 Updated Feb 4, 2025
  • protobuf-specs Public

    Protocol Buffer specifications

    sigstore/protobuf-specs’s past year of commit activity
    Rust 26 Apache-2.0 32 28 5 Updated Feb 5, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 126 57 53 15 Updated Feb 5, 2025
  • sigstore-ruby Public

    Pure-ruby implementation of sigstore verification

    sigstore/sigstore-ruby’s past year of commit activity
    Ruby 14 Apache-2.0 2 2 4 Updated Feb 5, 2025
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    sigstore/timestamp-authority’s past year of commit activity
    Go 79 Apache-2.0 40 8 1 Updated Feb 5, 2025
  • sigstore-probers Public

    Probers for sigstore infrastructure

    sigstore/sigstore-probers’s past year of commit activity
    Go 6 Apache-2.0 13 4 (1 issue needs help) 4 Updated Feb 5, 2025
  • sigstore Public

    Common go library shared across sigstore services and clients

    sigstore/sigstore’s past year of commit activity
    Go 462 Apache-2.0 124 36 11 Updated Feb 4, 2025