Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.7k 558

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 673 142

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 929 168

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 186 56

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 251 51

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 50 21

Repositories

Showing 10 of 60 repositories
  • gitsign Public

    Keyless Git signing using Sigstore

    sigstore/gitsign’s past year of commit activity
    Go 970 64 23 (1 issue needs help) 4 Updated Feb 3, 2025
  • helm-charts Public

    Helm charts for sigstore project

    sigstore/helm-charts’s past year of commit activity
    Smarty 69 Apache-2.0 93 31 20 Updated Feb 3, 2025
  • protobuf-specs Public

    Protocol Buffer specifications

    sigstore/protobuf-specs’s past year of commit activity
    Rust 26 Apache-2.0 32 28 9 Updated Feb 3, 2025
  • rekor-search-ui Public

    Search Rekor for entries

    sigstore/rekor-search-ui’s past year of commit activity
    TypeScript 30 Apache-2.0 24 5 6 Updated Feb 3, 2025
  • sigstore-ruby Public

    Pure-ruby implementation of sigstore verification

    sigstore/sigstore-ruby’s past year of commit activity
    Ruby 13 Apache-2.0 2 2 4 Updated Feb 3, 2025
  • model-transparency Public

    Supply chain security for ML

    sigstore/model-transparency’s past year of commit activity
    Python 126 Apache-2.0 32 27 (1 issue needs help) 3 Updated Feb 3, 2025
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    sigstore/scaffolding’s past year of commit activity
    HCL 61 Apache-2.0 58 9 10 Updated Feb 3, 2025
  • fulcio Public

    Sigstore OIDC PKI

    sigstore/fulcio’s past year of commit activity
    Go 673 Apache-2.0 142 50 (1 issue needs help) 12 Updated Feb 3, 2025
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 30 Apache-2.0 26 16 1 Updated Feb 3, 2025
  • sigstore-go Public

    Go library for Sigstore signing and verification

    sigstore/sigstore-go’s past year of commit activity
    Go 54 Apache-2.0 27 15 6 Updated Feb 3, 2025