cosign
https://github.com/sigstore/cosign
Go
Container Signing
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Go not yet supported2 Subscribers
Add a CodeTriage badge to cosign
Help out
- Issues
- Cosign can't verify by local key exported from HashiVault
- Why not using an empty configuration for the signature on OCI 1.1?
- Support AES management key on YubiKeys with 5.7.x firmware
- Cosign Verify fails with azure akv intermittent
- Cosign Verify fails with azure akv intermittent
- Cosign should check Media Type of the layer before download of the signature
- Bypass YubiKey Authentication for Self-Generated Key Pairs
- Why calling v2 referrers api and including all signature layer in new signature manifest
- Enable annotations to be set on attestations and signatures when OCI artifacts are uploaded
- Support working with SLSA statements (without wrapping)
- Docs
- Go not yet supported