Skip to content

Common library shared across sigstore services

License

Notifications You must be signed in to change notification settings

zosocanuck/sigstore

 
 

Repository files navigation

sigstore framework

Updated to support PKCS#11

⚠️ Not ready for use yet!

sigstore/sigstore is a generic library that is utilized by various other clients and projects inc fulcio (webPKI), cosign (container and OCI signing tool) and tektoncd/chains (Supply Chain Security in Tekton Pipelines).

sigstore is also good candidate for anyone wanting to develop go based clients / systems and utilise exiting go modules for common sigstore functionality.

Security

Should you discover any security issues, please refer to sigstores security process

For container signing, you want cosign

About

Common library shared across sigstore services

Resources

License

Code of conduct

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Go 98.9%
  • Other 1.1%