Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 5.7k 691

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 801 168

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 1.1k 197

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 220 71

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 311 75

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 72 25

Repositories

Showing 10 of 65 repositories
  • cosign Public

    Code signing and transparency for containers and binaries

    sigstore/cosign’s past year of commit activity
    Go 5,652 Apache-2.0 691 274 (1 issue needs help) 29 Updated Feb 16, 2026
  • model-validation-operator Public

    Kubernetes controller to validate AI models

    sigstore/model-validation-operator’s past year of commit activity
    Go 26 Apache-2.0 10 9 3 Updated Feb 16, 2026
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 178 Apache-2.0 39 5 8 Updated Feb 16, 2026
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    sigstore/scaffolding’s past year of commit activity
    Go 72 Apache-2.0 63 9 3 Updated Feb 16, 2026
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 118 Apache-2.0 91 19 0 Updated Feb 16, 2026
  • rekor Public

    Software Supply Chain Transparency Log

    sigstore/rekor’s past year of commit activity
    Go 1,078 Apache-2.0 197 72 4 Updated Feb 16, 2026
  • model-transparency Public

    Supply chain security for ML

    sigstore/model-transparency’s past year of commit activity
    Python 219 Apache-2.0 60 30 (1 issue needs help) 7 Updated Feb 16, 2026
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 47 Apache-2.0 34 10 0 Updated Feb 16, 2026
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    sigstore/timestamp-authority’s past year of commit activity
    Go 114 Apache-2.0 54 4 1 Updated Feb 16, 2026
  • sigstore-go Public

    Go library for Sigstore signing and verification

    sigstore/sigstore-go’s past year of commit activity
    Go 83 Apache-2.0 44 10 9 Updated Feb 16, 2026