Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.9k 583

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 716 148

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 952 176

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 188 58

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 260 56

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 54 21

Repositories

Showing 10 of 62 repositories
  • sigstore-rs Public

    An experimental Rust crate for sigstore

    sigstore/sigstore-rs’s past year of commit activity
    Rust 188 Apache-2.0 58 39 (11 issues need help) 12 Updated Apr 28, 2025
  • sigstore Public

    Common go library shared across sigstore services and clients

    sigstore/sigstore’s past year of commit activity
    Go 483 Apache-2.0 134 18 12 Updated Apr 28, 2025
  • github-sync Public

    Pulumi GitHub Sync for sigstore

    sigstore/github-sync’s past year of commit activity
    Go 6 Apache-2.0 4 0 1 Updated Apr 28, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 131 63 55 10 Updated Apr 28, 2025
  • cosign Public

    Code signing and transparency for containers and binaries

    sigstore/cosign’s past year of commit activity
    Go 4,891 Apache-2.0 583 241 (1 issue needs help) 26 Updated Apr 28, 2025
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 161 Apache-2.0 26 5 8 Updated Apr 28, 2025
  • sigstore-devops-tools Public

    Tools & services used to help in the development flow of sigstore

    sigstore/sigstore-devops-tools’s past year of commit activity
    Go 6 Apache-2.0 3 0 1 Updated Apr 28, 2025
  • rekor Public

    Software Supply Chain Transparency Log

    sigstore/rekor’s past year of commit activity
    Go 952 Apache-2.0 176 72 2 Updated Apr 28, 2025
  • model-transparency Public

    Supply chain security for ML

    sigstore/model-transparency’s past year of commit activity
    Python 155 Apache-2.0 35 22 (2 issues need help) 1 Updated Apr 28, 2025
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 31 Apache-2.0 29 12 3 Updated Apr 28, 2025