Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 5.7k 711

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 814 167

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 1.1k 196

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 224 70

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 316 77

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 74 27

Repositories

Showing 10 of 66 repositories
  • model-validation-operator Public

    Kubernetes controller to validate AI models

    sigstore/model-validation-operator’s past year of commit activity
    Go 27 Apache-2.0 11 9 2 Updated Mar 23, 2026
  • rekor-tiles Public

    Signature Transparency Log designed for ease of use, low cost, and minimal maintenance

    sigstore/rekor-tiles’s past year of commit activity
    Go 35 Apache-2.0 19 33 4 Updated Mar 23, 2026
  • sigstore-probers Public

    Probers for sigstore infrastructure

    sigstore/sigstore-probers’s past year of commit activity
    Go 6 Apache-2.0 18 3 0 Updated Mar 23, 2026
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 120 Apache-2.0 92 20 1 Updated Mar 23, 2026
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    sigstore/root-signing-staging’s past year of commit activity
    10 Apache-2.0 11 7 1 Updated Mar 23, 2026
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 178 Apache-2.0 42 5 9 Updated Mar 23, 2026
  • sigstore-devops-tools Public

    Tools & services used to help in the development flow of sigstore

    sigstore/sigstore-devops-tools’s past year of commit activity
    Go 7 Apache-2.0 3 0 2 Updated Mar 23, 2026
  • sigstore-rust Public

    Sigstore implemented in Rust for Github v0.3 bundles

    sigstore/sigstore-rust’s past year of commit activity
    Rust 6 Apache-2.0 4 2 7 Updated Mar 23, 2026
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 49 Apache-2.0 34 10 1 Updated Mar 23, 2026
  • model-transparency Public

    Supply chain security for ML

    sigstore/model-transparency’s past year of commit activity
    Python 225 Apache-2.0 60 31 (1 issue needs help) 9 Updated Mar 23, 2026