Skip to content

cosign

Artifact Management

A tool for signing and verifying OCI container images and other artifacts using Sigstore's keyless signing infrastructure

Go Latest v3.1.2 · 9d ago Security brief →

Features

  • Keyless signing with Sigstore Fulcio CA and Rekor transparency log
  • Support for hardware/KMS, custom keypair, and bring-your-own PKI signing
  • Container image signing, verification, and signature storage in OCI registries

Recent releases

View all 8 releases →
Review required
v3.1.2 Breaking risk
Auth Breaking upgrade

--payload deprecation + bundle inspect + cleanup

No immediate action
v2.6.4 Bug fix

OCI fixes + attestation download

Config change
v3.1.1 Breaking risk
Breaking upgrade

Flags deprecation + Rekor v2 + verify fixes

v3.0.6 Mixed patches GHSA-w6c6-c85g-mmv6
Security fixes
  • Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6)
Notable features
  • Add support for GCE metadata server env var
  • support managed keys in conformance testing
  • support key creation in GitLab group
v2.6.3 Security relevant patches GHSA-w6c6-c85g-mmv6
Security fixes
  • Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
6,141
Forks
770
Languages
Go Shell Makefile

Install & Platforms

Install via
brew binary docker go
Platforms
linux macos

Community & Support

Beta — feedback welcome: [email protected]