Skip to content
@sigstore

sigstore

Software Supply Chain Security
sigstore logo

Sign. Verify. Protect. Making sure your software is what it claims to be.

Learn more at https://sigstore.dev/

Pinned Loading

  1. cosign cosign Public

    Code signing and transparency for containers and binaries

    Go 5.5k 673

  2. fulcio fulcio Public

    Sigstore OIDC PKI

    Go 775 162

  3. rekor rekor Public

    Software Supply Chain Transparency Log

    Go 1k 193

  4. sigstore-rs sigstore-rs Public

    An experimental Rust crate for sigstore

    Rust 216 67

  5. sigstore-python sigstore-python Public

    A Sigstore client written in Python

    Python 299 64

  6. sigstore-java sigstore-java Public

    java clients for sigstore

    Java 68 25

Repositories

Showing 10 of 65 repositories
  • terraform-modules Public

    Terraform modules for Sigstore cloud infrastructure

    sigstore/terraform-modules’s past year of commit activity
    HCL 3 Apache-2.0 7 1 3 Updated Dec 15, 2025
  • gh-action-sigstore-python Public

    A GitHub Action for sigstore-python

    sigstore/gh-action-sigstore-python’s past year of commit activity
    Python 62 Apache-2.0 14 11 0 Updated Dec 15, 2025
  • sigstore-rs Public

    An experimental Rust crate for sigstore

    sigstore/sigstore-rs’s past year of commit activity
    Rust 216 Apache-2.0 67 45 (11 issues need help) 16 Updated Dec 15, 2025
  • fulcio Public

    Sigstore OIDC PKI

    sigstore/fulcio’s past year of commit activity
    Go 775 Apache-2.0 162 51 (1 issue needs help) 1 Updated Dec 15, 2025
  • sigstore Public

    Common go library shared across sigstore services and clients

    sigstore/sigstore’s past year of commit activity
    Go 492 Apache-2.0 142 20 21 Updated Dec 15, 2025
  • cosign-installer Public

    Cosign Github Action

    sigstore/cosign-installer’s past year of commit activity
    172 Apache-2.0 50 3 4 Updated Dec 15, 2025
  • policy-controller Public

    Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

    sigstore/policy-controller’s past year of commit activity
    Go 150 68 61 14 Updated Dec 16, 2025
  • timestamp-authority Public

    RFC3161 Timestamp Authority

    sigstore/timestamp-authority’s past year of commit activity
    Go 106 Apache-2.0 50 3 1 Updated Dec 15, 2025
  • scaffolding Public

    Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.

    sigstore/scaffolding’s past year of commit activity
    Go 68 Apache-2.0 63 9 5 Updated Dec 15, 2025
  • rekor-monitor Public

    Log monitor for Rekor to verify immutability and monitor entries

    sigstore/rekor-monitor’s past year of commit activity
    Go 39 Apache-2.0 33 11 2 Updated Dec 15, 2025