Software Supply Chain

Sigstore

Foundation Global OpenSSF Since 2021

Signing infrastructure for software artefacts using short-lived certificates tied to an OIDC identity, with signatures recorded in a public transparency log.

The keyless model is why it gets adopted: no long-lived signing key to protect, and the transparency log gives an auditor something to check independently.

At a glance

Category
Software Supply Chain
Jurisdiction
Global
Governance
OpenSSF
Status
Production; Fulcio, Rekor and Cosign
First released
2021

Links

Related frameworks

Other entries under Software Supply Chain.

See Sigstore in context

Open the interactive Data Landscape for Regulation to compare Sigstore against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.