Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign Public

    Code signing and transparency for containers and binaries

    Go 4.8k 577

  2. fulcio Public

    Sigstore OIDC PKI

    Go 703 147

  3. rekor Public

    Software Supply Chain Transparency Log

    Go 946 176

  4. sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 186 58

  5. sigstore-python Public

    A Sigstore client written in Python

    Python 258 54

  6. sigstore-java Public

    java clients for sigstore

    Java 54 21

Repositories

Showing 10 of 62 repositories
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    Go 87 Apache-2.0 40 5 4 Updated Apr 9, 2025
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    7 Apache-2.0 7 7 1 Updated Apr 9, 2025
  • protobuf-specs Public

    Sigstore's Protocol Buffer specifications

    Makefile 27 Apache-2.0 34 31 13 Updated Apr 9, 2025
  • sigstore-python Public

    A Sigstore client written in Python

    Python 258 54 34 (1 issue needs help) 1 Updated Apr 8, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    Go 129 60 54 10 Updated Apr 8, 2025
  • sigstore Public

    Common go library shared across sigstore services and clients

    Go 480 Apache-2.0 131 18 4 Updated Apr 8, 2025
  • rekor-tiles Public

    Signature Transparency Log designed for ease of use, low cost, and minimal maintenance

    Go 6 Apache-2.0 8 78 3 Updated Apr 8, 2025
  • model-transparency Public

    Supply chain security for ML

    Python 147 Apache-2.0 34 22 (2 issues need help) 2 Updated Apr 8, 2025
  • community Public

    General sigstore community repo

    41 Apache-2.0 49 16 1 Updated Apr 8, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    Makefile 97 Apache-2.0 84 15 0 Updated Apr 8, 2025