CosignSigstore
Open sourceSigstore CLI for signing and verifying container images and artifacts and attaching attestations to registries.
Sigstore CLI for signing and verifying container images and artifacts and attaching attestations to registries.
Reusable GitHub Actions that automatically produce signed SLSA provenance attestations for build artifacts.
Open source framework for protecting software supply chain integrity through attestations.