Software Supply Chain
Sigstore
Foundation
Global
OpenSSF
Since 2021
Signing infrastructure for software artefacts using short-lived certificates tied to an OIDC identity, with signatures recorded in a public transparency log.
The keyless model is why it gets adopted: no long-lived signing key to protect, and the transparency log gives an auditor something to check independently.
At a glance
- Category
- Software Supply Chain
- Jurisdiction
- Global
- Governance
- OpenSSF
- Status
- Production; Fulcio, Rekor and Cosign
- First released
- 2021
Links
Related frameworks
Other entries under Software Supply Chain.
- SPDX: System Package Data Exchange
- CycloneDX: CycloneDX Bill of Materials
- SLSA: Supply-chain Levels for Software Artifacts
- in-toto: in-toto Attestation Framework
See Sigstore in context
Open the interactive Data Landscape for Regulation to compare Sigstore against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.