Cosign

B
B tier on Code Signing SoftwareScore 7.3 · #1 of 26
Android app
Not listed
Free plan
Yes
Runs on
Linux, Mac, self-hosted, Windows
github.com
The Cosign homepage

Summary

Cosign is a free tool for signing and verifying OCI container images and other software artifacts. It can store container signatures alongside images in an OCI registry and publish generic artifacts through OCI. Its supported targets include blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, eBPF modules, and in-toto attestations, whose payloads use DSSE signatures. The default keyless method uses temporary keys kept in memory, short-lived certificates from Sigstore’s Fulcio service, and entries in the Rekor transparency log. Other options include hardware and KMS signing, encrypted keypairs generated by Cosign, and user-provided PKI. The tool supports CI/CD signing, with installation guidance for GitHub Actions and GitLab CI/CD. Offline verification is possible when the image and signature materials are available locally and a trusted root is supplied. Cosign is described as a legacy signing system that remains in use for signing, while Sigstore-go is recommended for verification integrations. Its CLI-oriented design has no API stability guarantees, and the documentation does not recommend it for application integration.

Who it is for

Cosign suits open-source package managers and teams that need to sign or verify artifacts in registry and CI/CD workflows. It is less suited to developers seeking a stable API for direct application integration.

What is good

  • Supports keyless signing through Sigstore services
  • Works with hardware and KMS signing
  • Supports GitHub Actions and GitLab CI/CD
  • Can verify signatures offline with local materials

What to know first

  • Not recommended for application integration
  • Verification integrations are directed to Sigstore-go
  • Public transparency logs may reveal signer identity

Everything Xiaomi review

Cosign: the full review

Cosign offers several signing paths and supports a broad set of software artifacts. Its legacy status and CLI-focused design matter for teams planning new integrations.

Overview

Cosign is an open-source tool for signing and verifying OCI containers and other software artifacts. It is best suited to teams that can work through a CLI, especially open-source package managers building artifact-signing workflows. Its broad signing options are useful, but its legacy status and lack of API stability make it a poor fit for new application integrations.

Key features

Cosign’s default keyless signing uses Sigstore’s public-good Fulcio certificate authority and Rekor transparency log. It creates ephemeral keys held in memory, obtains short-lived certificates, and records signatures in the log. That avoids managing a persistent signing key for this path, but signing can publish identity information such as an account email in a public log, where it cannot later be removed.

Teams that need control over key custody can use hardware or KMS signing, Cosign-generated encrypted keypairs, or bring their own PKI. Cosign generates ECDSA-P256 keys and uses SHA256 hashes for ephemeral keyless and managed-key signing, so those limits matter when a workflow requires other algorithms or hashes.

Container signatures can be stored alongside images in an OCI registry. Cosign also provides utilities for publishing generic artifacts through OCI and supports in-toto attestations whose payloads are signed with DSSE. Supported targets include container images, blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, eBPF modules, and in-toto attestations. This breadth makes it relevant beyond container release pipelines, though teams should expect to operate it as a CLI tool rather than depend on it as a stable application API.

Tested registry integrations include AWS ECR, Google Artifact Registry, Docker Hub, Azure Container Registry, GitLab Container Registry, and GitHub Container Registry. Installation guidance covers GitHub Actions and GitLab CI/CD pipelines. Offline verification is possible when the image and signature materials are local and a trusted root is supplied. The installation guide also recommends verifying downloaded Cosign binaries; releases are signed with keyless signing and an artifact key.

Pricing

Cosign is free open-source software: the Cosign plan is 0.00 USD per free, billed Free. There is no free trial, and no hosted service or usage limits are stated. That makes it a practical option for teams willing to run and integrate the tool themselves, rather than buyers seeking a hosted signing service.

Platforms

Cosign supports Linux, macOS, Windows, and self-hosted use. The project links Linux and macOS release binaries and documents installation through Go, Homebrew, Arch, Alpine, Nix, GitHub Actions, GitLab, and container images. The range gives teams several routes to add it to development and CI environments, while the documented release binaries are for Linux and macOS.

Who it's for

Cosign is a strong fit for open-source package managers and release teams that need to sign and verify artifacts across OCI registries, CI pipelines, or offline environments. Its multiple key-management paths suit teams with different custody requirements. It is less suitable for developers who need a supported API for embedding signing or verification in an application: Cosign’s functions were designed for its CLI, the project makes no API stability guarantees, and it recommends Sigstore-go for verification integrations.

Pros and cons

  • Pros: Keyless, hardware, KMS, encrypted-keypair, and bring-your-own-PKI options let teams choose a signing approach suited to their key-management needs.
  • Pros: OCI registry storage, generic artifact publishing, and in-toto attestations cover container and broader software-supply-chain workflows.
  • Pros: Offline verification is available when signature materials and a trusted root are available locally.
  • Cons: Public transparency logging can expose signer identity information that cannot later be removed.
  • Cons: CLI-focused design and the absence of API stability guarantees make Cosign a weak choice for new application integrations.
  • Cons: Signing is constrained to ECDSA-P256 keys and SHA256 hashes for ephemeral keyless and managed-key signing.
  • Cons: The project describes Cosign as a legacy system: it remains intended for signing, while Sigstore-go is recommended for verification integrations.

Alternatives

Compare code signing software if you want to weigh tools across the category. Sigstore is the direct alternative to consider for a broader Sigstore choice; its free plan is available to all developers and software providers.

Choose SignPath if an eligible open-source project wants a free code-signing option; its open-source plan has eligibility conditions. SignPath Foundation is another free option for eligible, actively maintained open-source projects released under an OSI-approved license, with manual release requirements.

SignServer may suit teams looking for community signing and timestamping with source-code or container deployment; its community plan covers basic code, document, and container signing. Consider Bamboo Deploy if its freemium offering fits: Premium costs 15.00 USD per month, billed $45 every 3 months, and includes up to 50 apps and 1GB cloud hosting.

DigiCert Software Trust Manager is a paid alternative with custom pricing. Red Hat Trusted Artifact Signer is another paid option with custom pricing. SSL.com Certificate Lifecycle Management is a freemium alternative without a free plan.

Verdict

Choose Cosign if your team needs free, flexible signing and verification for containers and other artifacts and is comfortable operating a CLI-centered tool. Its registry support, key options, attestations, and offline verification give it meaningful breadth. Look elsewhere if you need a stable API for a new application integration, or if the public-log identity exposure and signing algorithm limits do not suit your security requirements.

Cosign plans and pricing

All plans
Cosign Free Free; open-source software No hosted service or usage limits stated github.com · 3 Oct 2026

Compared on code signing software

Free plan
Yesgithub.com
Supported targets
OCI container images, blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, eBPF modules, and In-Toto attestationsgithub.com
Certificate provided
Yesgithub.com
Cloud signing
Nogithub.com
HSM key protection
Yesgithub.com
Trusted timestamping
Yesgithub.com
CI/CD signing
Yesgithub.com

Facts

Purpose
Cosign signs and verifies OCI containers and other software artifacts.github.com · 2 Oct 2026
Keyless signing
Its default keyless signing uses Sigstore’s public-good Fulcio certificate authority and Rekor transparency log.github.com · 2 Oct 2026
Key options
Cosign supports hardware and KMS signing, encrypted keypairs it generates, and bring-your-own PKI.github.com · 2 Oct 2026
Registry storage
It can sign, verify, and store container signatures in an OCI registry.github.com · 2 Oct 2026
Artifact types
Cosign includes utilities for publishing generic artifacts through OCI and supports in-toto attestations.github.com · 2 Oct 2026
Registry integrations
The project lists tested registries including AWS ECR, Google Artifact Registry, Docker Hub, Azure Container Registry, GitLab Container Registry, and GitHub Container Registry.github.com · 2 Oct 2026
CI integrations
Installation guidance covers using Cosign in GitHub Actions and GitLab CI/CD pipelines.docs.sigstore.dev · 2 Oct 2026
Security verification
The installation guide recommends verifying downloaded Cosign binaries; releases are signed with keyless signing and an artifact key.docs.sigstore.dev · 2 Oct 2026
Offline verification
Cosign can verify signatures offline when the image and signature materials are available locally and a trusted root is supplied.github.com · 2 Oct 2026
Support
The project directs users with problems to open a GitHub issue or ask in the Sigstore Slack channel.github.com · 2 Oct 2026
Intended users
The Sigstore integration guidance identifies open-source package managers as primary stakeholders for artifact signing and verification workflows.docs.sigstore.dev · 2 Oct 2026
Development status
Cosign is described as a legacy system that should still be used for signing, while Sigstore-go is recommended for verification integrations.docs.sigstore.dev · 2 Oct 2026
Integration limitation
Cosign functions were designed for its CLI rather than as an API; the documentation says there are no API stability guarantees and does not recommend Cosign for application integration.docs.sigstore.dev · 2 Oct 2026
Signing limitation
Cosign generates only ECDSA-P256 keys and uses SHA256 hashes for ephemeral keyless and managed-key signing.github.com · 2 Oct 2026
Artifact storage
Container signatures can be stored alongside images in an OCI registry, and Cosign also provides utilities for publishing generic artifacts through OCI.github.com · 3 Oct 2026
Attestations
Cosign supports in-toto attestations, with payloads signed using DSSE.github.com · 3 Oct 2026
Platforms and installation
The project links Linux and macOS release binaries and documents installation through Go, Homebrew, Arch, Alpine, Nix, GitHub Actions, GitLab, and container images.docs.sigstore.dev · 3 Oct 2026
Security model
For keyless signing, Cosign uses ephemeral keys held in memory, short-lived Fulcio certificates, and Rekor transparency log entries.docs.sigstore.dev · 3 Oct 2026
Public log privacy
The quick start warns that signing may place identity information such as an account email in public transparency logs, where it cannot later be removed.github.com · 3 Oct 2026
Notable limit
Cosign generates ECDSA-P256 keys and uses SHA256 hashes for ephemeral keyless and managed-key signing.github.com · 3 Oct 2026
Security reporting
Sigstore asks vulnerability reporters to email [email protected] and says the Security Response Committee will acknowledge reports within 24 hours.github.com · 3 Oct 2026

Best Cosign alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Cosign yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources