Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 5.5k 671

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 772 162

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 1k 193

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 215 67

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 299 64

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 68 25

Repositories

Showing 10 of 65 repositories
  • gh-action-sigstore-python Public

    A GitHub Action for sigstore-python

    sigstore/gh-action-sigstore-python’s past year of commit activity
    Python 62 Apache-2.0 14 11 2 Updated Dec 8, 2025
  • sigstore-java Public

    java clients for sigstore

    sigstore/sigstore-java’s past year of commit activity
    Java 68 Apache-2.0 25 24 5 Updated Dec 8, 2025
  • root-signing Public

    TUF repository for Sigstore trust root

    sigstore/root-signing’s past year of commit activity
    Makefile 112 Apache-2.0 88 18 1 Updated Dec 8, 2025
  • sigstore-rs Public

    An experimental Rust crate for sigstore

    sigstore/sigstore-rs’s past year of commit activity
    Rust 215 Apache-2.0 67 45 (11 issues need help) 16 Updated Dec 8, 2025
  • cosign Public

    Code signing and transparency for containers and binaries

    sigstore/cosign’s past year of commit activity
    Go 5,475 Apache-2.0 671 261 (1 issue needs help) 13 Updated Dec 8, 2025
  • model-validation-operator Public

    Kubernetes controller to validate AI models

    sigstore/model-validation-operator’s past year of commit activity
    Go 25 Apache-2.0 8 12 8 Updated Dec 8, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 149 68 61 14 Updated Dec 8, 2025
  • github-sync Public

    Pulumi GitHub Sync for sigstore

    sigstore/github-sync’s past year of commit activity
    Go 6 Apache-2.0 4 0 2 Updated Dec 8, 2025
  • sigstore-conformance Public

    Conformance testing for Sigstore clients

    sigstore/sigstore-conformance’s past year of commit activity
    Python 11 16 30 2 Updated Dec 8, 2025
  • model-transparency Public

    Supply chain security for ML

    sigstore/model-transparency’s past year of commit activity
    Python 210 Apache-2.0 53 25 (1 issue needs help) 6 Updated Dec 8, 2025