Sigstore
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted, Windows

Summary
Sigstore is a free, open source project focused on software supply chain security. Developers can use it to sign and verify release files, container images, binaries, software bills of materials, and other artifacts. Signing uses temporary keys, so developers do not need to manage signing keys themselves. Signing events are entered into a public, tamper-resistant log for auditing. Its components include Cosign, Fulcio, Rekor, OpenID Connect, and Policy Controller: Cosign handles artifact signatures and verification, Fulcio issues temporary certificates to authorized identities, and Rekor stores searchable signed metadata. OpenID Connect authenticates users through providers such as GitHub and Google. Sigstore provides GitHub Actions and documents installation for GitLab CI, alongside official clients for Go, Java, JavaScript, Python, Ruby, and Rust. The trust root uses The Update Framework and is maintained by five keyholders drawn from different companies and academic institutions. Sigstore supports Linux, macOS, Windows, API, and self-hosted environments. Community assistance is available through Slack and GitHub issues. One integration caveat is that Cosign has no API stability guarantees and is not recommended for application integration because of its dependencies.
Who it is for
Sigstore suits developers and software providers seeking signing and verification workflows for software artifacts. It may also be relevant to package managers integrating signing into their tooling or registries.
What is good
- Free and open source.
- Uses temporary signing keys.
- Public log supports auditing signing events.
- Official clients cover six programming languages.
- GitHub Actions and GitLab CI guidance are available.
What to know first
- Cosign has no API stability guarantees.
- Cosign is not recommended for application integration.
- Community support is through Slack and GitHub issues.
Verdict
Sigstore combines artifact signing, identity-based certificates, and a public log in a free project. Developers planning application integrations should account for Cosign's stated API and dependency limitations.
Sigstore plans and pricing
All plansCompared on code signing software
- Free plan
- Yessigstore.dev
Facts
- Purpose
- Sigstore is an open source project for improving software supply chain security.docs.sigstore.dev · 30 Sept 2026
- Artifact coverage
- Sigstore supports signing and verifying release files, container images, binaries, software bills of materials and more.docs.sigstore.dev · 30 Sept 2026
- Key management
- Sigstore generates signatures with ephemeral signing keys, so developers do not need to manage keys.docs.sigstore.dev · 30 Sept 2026
- Transparency
- Signing events are recorded in a tamper-resistant public log so developers can audit signing events.docs.sigstore.dev · 30 Sept 2026
- Components
- Sigstore combines Cosign, Fulcio, Rekor, OpenID Connect and Policy Controller technologies.docs.sigstore.dev · 30 Sept 2026
- Cosign
- Cosign signs and verifies containers and other artifacts and stores signatures in an OCI registry.docs.sigstore.dev · 30 Sept 2026
- Fulcio
- Fulcio is a free root certification authority that issues temporary certificates to authorized identities and publishes them in Rekor.docs.sigstore.dev · 30 Sept 2026
- Rekor
- Rekor records signed metadata in a searchable ledger that cannot be tampered with.docs.sigstore.dev · 30 Sept 2026
- Identity
- Sigstore uses OpenID Connect to authenticate users through identity providers such as GitHub and Google.docs.sigstore.dev · 30 Sept 2026
- Trust root
- The Sigstore trust root uses The Update Framework and is maintained through a rotation of five keyholders from different companies and academic institutions.docs.sigstore.dev · 30 Sept 2026
- CI integrations
- Sigstore provides GitHub Actions for generating signatures and installing Cosign, and documents GitLab CI installation.docs.sigstore.dev · 30 Sept 2026
- Language clients
- Official language clients are available for Go, Java, JavaScript, Python, Ruby and Rust.docs.sigstore.dev · 30 Sept 2026
- Package-manager integration
- Sigstore identifies open source package managers as primary stakeholders and describes workflows for integrating signing and verification into package tooling and registries.docs.sigstore.dev · 30 Sept 2026
- Integration limitation
- Cosign has no API stability guarantees, does not follow semantic versioning, and is not recommended for application integration because of its dependencies.docs.sigstore.dev · 30 Sept 2026
- Support
- Community support is provided through Slack, and users can also open GitHub issues in the relevant repository.docs.sigstore.dev · 30 Sept 2026
Company
- Founded
- 2021sigstore.dev · 28 Sept 2026
Best Sigstore alternatives
See all 12Where it ranks on Everything Xiaomi
Is Sigstore yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- docs.sigstore.dev· checked 30 Sept 2026
- docs.sigstore.dev/about/tooling/· checked 30 Sept 2026
- docs.sigstore.dev/about/security/· checked 30 Sept 2026
- docs.sigstore.dev/about/faq/· checked 30 Sept 2026
- docs.sigstore.dev/language_clients/language_client_overvi· checked 30 Sept 2026
- docs.sigstore.dev/cosign/system_config/integration/· checked 30 Sept 2026
- docs.sigstore.dev/about/support/· checked 30 Sept 2026
- sigstore.dev· checked 28 Sept 2026
- linuxfoundation.org/press/press-release/linux-foundation-an· checked 30 Sept 2026




