Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.8k 568

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 690 143

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 942 174

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 185 57

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 256 55

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 53 22

Repositories

Showing 10 of 62 repositories
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 161 Apache-2.0 23 5 11 Updated Mar 10, 2025
  • rekor Public

    Software Supply Chain Transparency Log

    sigstore/rekor’s past year of commit activity
    Go 942 Apache-2.0 174 77 13 Updated Mar 10, 2025
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    sigstore/timestamp-authority’s past year of commit activity
    Go 81 Apache-2.0 40 6 7 Updated Mar 10, 2025
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 31 Apache-2.0 26 12 7 Updated Mar 10, 2025
  • sigstore-go Public

    Go library for Sigstore signing and verification

    sigstore/sigstore-go’s past year of commit activity
    Go 58 Apache-2.0 29 18 11 Updated Mar 10, 2025
  • sigstore-python Public

    A Sigstore client written in Python

    sigstore/sigstore-python’s past year of commit activity
    Python 256 55 33 (1 issue needs help) 4 Updated Mar 10, 2025
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    sigstore/scaffolding’s past year of commit activity
    HCL 62 Apache-2.0 60 9 2 Updated Mar 10, 2025
  • rekor-tiles Public

    Signature Transparency Log designed for ease of use, low cost, and minimal maintenance

    sigstore/rekor-tiles’s past year of commit activity
    Go 5 Apache-2.0 4 68 3 Updated Mar 10, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 95 Apache-2.0 83 16 0 Updated Mar 10, 2025
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    sigstore/root-signing-staging’s past year of commit activity
    7 Apache-2.0 7 6 0 Updated Mar 10, 2025