cosign
https://github.com/sigstore/cosign
Go
Container Signing
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Go not yet supported2 Subscribers
Add a CodeTriage badge to cosign
Help out
- Issues
- cosign attest retries mishandled
- VerifyRFC3161Timestamp silently drops user-provided TSA chain when TrustedMaterial is set (regression from v2)
- docs: add digest-based verification example for verify-blob-attestation
- Reason for --signing-config depending on --new-bundle-format not clear
- fix(layout): preserve manifest artifactType in index.json when saving
- `verify` output missing success indicators for BYO-PKI certificate chain validation and RFC3161 timestamp verification
- fix: update dependencies to use new azure sdk components
- Add --ignore-pkcs11-certificate sign option
- Enhancement: Add native Syft JSON support in cosign attest
- Make sure cosign release signing takes rekor v2 change into account
- Docs
- Go not yet supported