Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 5.1k 614

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 741 155

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 990 180

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 195 60

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 284 62

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 60 24

Repositories

Showing 10 of 63 repositories
  • rekor-tiles Public

    Signature Transparency Log designed for ease of use, low cost, and minimal maintenance

    sigstore/rekor-tiles’s past year of commit activity
    Go 17 Apache-2.0 8 66 3 Updated Aug 6, 2025
  • architecture-docs Public Forked from martinthomson/internet-draft-template

    Specification of sigstore's architecture in an IETF internet-draft format

    sigstore/architecture-docs’s past year of commit activity
    5 94 25 1 Updated Aug 6, 2025
  • rekor Public

    Software Supply Chain Transparency Log

    sigstore/rekor’s past year of commit activity
    Go 990 Apache-2.0 180 72 2 Updated Aug 6, 2025
  • sigstore-python Public

    A Sigstore client written in Python

    sigstore/sigstore-python’s past year of commit activity
    Python 284 62 54 (1 issue needs help) 3 Updated Aug 6, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 107 Apache-2.0 88 21 0 Updated Aug 6, 2025
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    sigstore/root-signing-staging’s past year of commit activity
    10 Apache-2.0 9 7 2 Updated Aug 6, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 140 64 56 8 Updated Aug 6, 2025
  • helm-sigstore Public

    Plugin for Helm to integrate the sigstore ecosystem

    sigstore/helm-sigstore’s past year of commit activity
    Go 65 Apache-2.0 14 2 0 Updated Aug 6, 2025
  • sigstore-devops-tools Public

    Tools & services used to help in the development flow of sigstore

    sigstore/sigstore-devops-tools’s past year of commit activity
    Go 6 Apache-2.0 3 0 0 Updated Aug 6, 2025
  • sigstore-ruby Public

    Pure-ruby implementation of sigstore verification

    sigstore/sigstore-ruby’s past year of commit activity
    Ruby 24 Apache-2.0 6 3 8 Updated Aug 6, 2025