Skip to content
cosign
Artifact Management
A tool for signing and verifying OCI container images and other artifacts using Sigstore's keyless signing infrastructure
Go
·
Latest v3.1.2 · 9d ago
Security brief →
Features
-
Keyless signing with Sigstore Fulcio CA and Rekor transparency log
-
Support for hardware/KMS, custom keypair, and bring-your-own PKI signing
-
Container image signing, verification, and signature storage in OCI registries
Review required
v3.1.2
Breaking risk
·
Auth
Breaking upgrade
--payload deprecation + bundle inspect + cleanup
No immediate action
v2.6.4
Bug fix
·
OCI fixes + attestation download
Config change
v3.1.1
Breaking risk
·
Breaking upgrade
Flags deprecation + Rekor v2 + verify fixes
v3.0.6
Mixed
patches GHSA-w6c6-c85g-mmv6
·
Security fixes
- Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6)
Notable features
- Add support for GCE metadata server env var
- support managed keys in conformance testing
- support key creation in GitLab group
v2.6.3
Security relevant
patches GHSA-w6c6-c85g-mmv6
·
Security fixes
- Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
Go
·
Shell
·
Makefile
View on GitHub
Documentation
Install & Platforms
Install via
brew
binary
docker
go
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open