Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign Public

    Code signing and transparency for containers and binaries

    Go 4.8k 570

  2. fulcio Public

    Sigstore OIDC PKI

    Go 694 144

  3. rekor Public

    Software Supply Chain Transparency Log

    Go 940 175

  4. sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 186 57

  5. sigstore-python Public

    A Sigstore client written in Python

    Python 256 55

  6. sigstore-java Public

    java clients for sigstore

    Java 53 21

Repositories

Showing 10 of 62 repositories
  • root-signing Public

    TUF repository for Sigstore trust root

    Makefile 95 Apache-2.0 84 15 0 Updated Mar 23, 2025
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    7 Apache-2.0 7 6 2 Updated Mar 22, 2025
  • gitsign Public

    Keyless Git signing using Sigstore

    Go 976 66 23 (1 issue needs help) 4 Updated Mar 22, 2025
  • sigstore-python Public

    A Sigstore client written in Python

    Python 256 55 33 (1 issue needs help) 1 Updated Mar 22, 2025
  • sigstore-probers Public

    Probers for sigstore infrastructure

    Go 6 Apache-2.0 13 4 (1 issue needs help) 3 Updated Mar 22, 2025
  • helm-sigstore Public

    Plugin for Helm to integrate the sigstore ecosystem

    Go 60 Apache-2.0 13 2 0 Updated Mar 22, 2025
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    HCL 62 Apache-2.0 60 10 11 Updated Mar 22, 2025
  • rekor-tiles Public

    Signature Transparency Log designed for ease of use, low cost, and minimal maintenance

    Go 5 Apache-2.0 6 75 5 Updated Mar 22, 2025
  • sigstore-devops-tools Public

    Tools & services used to help in the development flow of sigstore

    Go 6 Apache-2.0 3 0 2 Updated Mar 21, 2025
  • k8s-manifest-sigstore Public

    kubectl plugin for signing Kubernetes manifest YAML files with sigstore

    Go 80 Apache-2.0 21 1 4 Updated Mar 21, 2025