Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 5.1k 607

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 740 153

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 988 180

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 192 60

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 281 62

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 58 23

Repositories

Showing 10 of 63 repositories
  • fulcio Public

    Sigstore OIDC PKI

    sigstore/fulcio’s past year of commit activity
    Go 740 Apache-2.0 153 51 (2 issues need help) 5 Updated Jul 28, 2025
  • gitsign Public

    Keyless Git signing using Sigstore

    sigstore/gitsign’s past year of commit activity
    Go 1,010 70 24 (1 issue needs help) 1 Updated Jul 28, 2025
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    sigstore/scaffolding’s past year of commit activity
    Go 66 Apache-2.0 60 5 9 Updated Jul 28, 2025
  • rekor-search-ui Public

    Search Rekor for entries

    sigstore/rekor-search-ui’s past year of commit activity
    TypeScript 34 Apache-2.0 29 5 5 Updated Jul 28, 2025
  • protobuf-specs Public

    Sigstore's Protocol Buffer specifications

    sigstore/protobuf-specs’s past year of commit activity
    Makefile 33 Apache-2.0 40 33 5 Updated Jul 28, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 107 Apache-2.0 88 21 0 Updated Jul 28, 2025
  • sigstore-java Public

    java clients for sigstore

    sigstore/sigstore-java’s past year of commit activity
    Java 58 Apache-2.0 23 27 14 Updated Jul 28, 2025
  • sigstore-js Public

    Code-signing for npm packages

    sigstore/sigstore-js’s past year of commit activity
    TypeScript 165 Apache-2.0 31 5 3 Updated Jul 28, 2025
  • root-signing-staging Public

    Staging TUF repository for Sigstore trust root

    sigstore/root-signing-staging’s past year of commit activity
    10 Apache-2.0 9 7 1 Updated Jul 27, 2025
  • model-validation-operator Public

    Kubernetes controller to validate AI models

    sigstore/model-validation-operator’s past year of commit activity
    Go 21 Apache-2.0 5 7 2 Updated Jul 25, 2025