Sigstore

B
B tier on Code Signing SoftwareScore 7.0 · #4 of 26
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, Mac, self-hosted, Windows
sigstore.dev
The Sigstore homepage

Summary

Sigstore is a free, open source project focused on software supply chain security. Developers can use it to sign and verify release files, container images, binaries, software bills of materials, and other artifacts. Signing uses temporary keys, so developers do not need to manage signing keys themselves. Signing events are entered into a public, tamper-resistant log for auditing. Its components include Cosign, Fulcio, Rekor, OpenID Connect, and Policy Controller: Cosign handles artifact signatures and verification, Fulcio issues temporary certificates to authorized identities, and Rekor stores searchable signed metadata. OpenID Connect authenticates users through providers such as GitHub and Google. Sigstore provides GitHub Actions and documents installation for GitLab CI, alongside official clients for Go, Java, JavaScript, Python, Ruby, and Rust. The trust root uses The Update Framework and is maintained by five keyholders drawn from different companies and academic institutions. Sigstore supports Linux, macOS, Windows, API, and self-hosted environments. Community assistance is available through Slack and GitHub issues. One integration caveat is that Cosign has no API stability guarantees and is not recommended for application integration because of its dependencies.

Who it is for

Sigstore suits developers and software providers seeking signing and verification workflows for software artifacts. It may also be relevant to package managers integrating signing into their tooling or registries.

What is good

  • Free and open source.
  • Uses temporary signing keys.
  • Public log supports auditing signing events.
  • Official clients cover six programming languages.
  • GitHub Actions and GitLab CI guidance are available.

What to know first

  • Cosign has no API stability guarantees.
  • Cosign is not recommended for application integration.
  • Community support is through Slack and GitHub issues.

Verdict

Sigstore combines artifact signing, identity-based certificates, and a public log in a free project. Developers planning application integrations should account for Cosign's stated API and dependency limitations.

Sigstore plans and pricing

All plans
Free Free free to use for all developers and software providers linuxfoundation.org · 30 Sept 2026

Compared on code signing software

Free plan
Yessigstore.dev

Facts

Purpose
Sigstore is an open source project for improving software supply chain security.docs.sigstore.dev · 30 Sept 2026
Artifact coverage
Sigstore supports signing and verifying release files, container images, binaries, software bills of materials and more.docs.sigstore.dev · 30 Sept 2026
Key management
Sigstore generates signatures with ephemeral signing keys, so developers do not need to manage keys.docs.sigstore.dev · 30 Sept 2026
Transparency
Signing events are recorded in a tamper-resistant public log so developers can audit signing events.docs.sigstore.dev · 30 Sept 2026
Components
Sigstore combines Cosign, Fulcio, Rekor, OpenID Connect and Policy Controller technologies.docs.sigstore.dev · 30 Sept 2026
Cosign
Cosign signs and verifies containers and other artifacts and stores signatures in an OCI registry.docs.sigstore.dev · 30 Sept 2026
Fulcio
Fulcio is a free root certification authority that issues temporary certificates to authorized identities and publishes them in Rekor.docs.sigstore.dev · 30 Sept 2026
Rekor
Rekor records signed metadata in a searchable ledger that cannot be tampered with.docs.sigstore.dev · 30 Sept 2026
Identity
Sigstore uses OpenID Connect to authenticate users through identity providers such as GitHub and Google.docs.sigstore.dev · 30 Sept 2026
Trust root
The Sigstore trust root uses The Update Framework and is maintained through a rotation of five keyholders from different companies and academic institutions.docs.sigstore.dev · 30 Sept 2026
CI integrations
Sigstore provides GitHub Actions for generating signatures and installing Cosign, and documents GitLab CI installation.docs.sigstore.dev · 30 Sept 2026
Language clients
Official language clients are available for Go, Java, JavaScript, Python, Ruby and Rust.docs.sigstore.dev · 30 Sept 2026
Package-manager integration
Sigstore identifies open source package managers as primary stakeholders and describes workflows for integrating signing and verification into package tooling and registries.docs.sigstore.dev · 30 Sept 2026
Integration limitation
Cosign has no API stability guarantees, does not follow semantic versioning, and is not recommended for application integration because of its dependencies.docs.sigstore.dev · 30 Sept 2026
Support
Community support is provided through Slack, and users can also open GitHub issues in the relevant repository.docs.sigstore.dev · 30 Sept 2026

Company

Founded
2021sigstore.dev · 28 Sept 2026

Best Sigstore alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Sigstore yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources