Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.9k 580

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 706 147

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 948 176

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 187 58

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 258 55

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 54 21

Repositories

Showing 10 of 62 repositories
  • sigstore Public

    Common go library shared across sigstore services and clients

    sigstore/sigstore’s past year of commit activity
    Go 480 Apache-2.0 131 18 10 Updated Apr 15, 2025
  • rekor Public

    Software Supply Chain Transparency Log

    sigstore/rekor’s past year of commit activity
    Go 948 Apache-2.0 176 76 2 Updated Apr 15, 2025
  • cosign Public

    Code signing and transparency for containers and binaries

    sigstore/cosign’s past year of commit activity
    Go 4,853 Apache-2.0 580 241 (1 issue needs help) 23 Updated Apr 15, 2025
  • protobuf-specs Public

    Sigstore's Protocol Buffer specifications

    sigstore/protobuf-specs’s past year of commit activity
    Makefile 28 Apache-2.0 36 31 9 Updated Apr 15, 2025
  • sigstore-probers Public

    Probers for sigstore infrastructure

    sigstore/sigstore-probers’s past year of commit activity
    Go 6 Apache-2.0 13 8 (1 issue needs help) 2 Updated Apr 15, 2025
  • sigstore-java Public

    java clients for sigstore

    sigstore/sigstore-java’s past year of commit activity
    Java 54 Apache-2.0 21 23 11 Updated Apr 14, 2025
  • sigstore-go Public

    Go library for Sigstore signing and verification

    sigstore/sigstore-go’s past year of commit activity
    Go 61 Apache-2.0 31 17 8 Updated Apr 14, 2025
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    sigstore/timestamp-authority’s past year of commit activity
    Go 87 Apache-2.0 40 5 4 Updated Apr 14, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 129 61 55 8 Updated Apr 14, 2025
  • k8s-manifest-sigstore Public

    kubectl plugin for signing Kubernetes manifest YAML files with sigstore

    sigstore/k8s-manifest-sigstore’s past year of commit activity
    Go 80 Apache-2.0 21 1 5 Updated Apr 14, 2025