Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 4.7k 564

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 680 142

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 936 171

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 185 56

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 254 52

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 51 22

Repositories

Showing 10 of 61 repositories
  • model-transparency Public

    Supply chain security for ML

    sigstore/model-transparency’s past year of commit activity
    Python 130 Apache-2.0 32 26 (1 issue needs help) 3 Updated Feb 24, 2025
  • fulcio Public

    Sigstore OIDC PKI

    sigstore/fulcio’s past year of commit activity
    Go 680 Apache-2.0 142 50 (1 issue needs help) 7 Updated Feb 24, 2025
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    sigstore/scaffolding’s past year of commit activity
    HCL 61 Apache-2.0 58 10 11 Updated Feb 24, 2025
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 160 Apache-2.0 23 5 9 Updated Feb 24, 2025
  • protobuf-specs Public

    Protocol Buffer specifications

    sigstore/protobuf-specs’s past year of commit activity
    Rust 27 Apache-2.0 32 28 6 Updated Feb 23, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 96 Apache-2.0 83 15 0 Updated Feb 23, 2025
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    sigstore/root-signing-staging’s past year of commit activity
    7 Apache-2.0 7 6 0 Updated Feb 23, 2025
  • sigstore-java Public

    java clients for sigstore

    sigstore/sigstore-java’s past year of commit activity
    Java 51 Apache-2.0 22 23 14 Updated Feb 22, 2025
  • community Public

    General sigstore community repo

    sigstore/community’s past year of commit activity
    41 Apache-2.0 49 16 1 Updated Feb 22, 2025
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    sigstore/timestamp-authority’s past year of commit activity
    Go 80 Apache-2.0 39 8 4 Updated Feb 22, 2025