/sigstore

Signing prototype

Primary LanguageGoApache License 2.0Apache-2.0

sigstore signing CLI tool

⚠️ Not ready for use yet!

sigstore CLI is a generic tool to sign blobs, tarballs etc and establish a trust root using the sigstore signing infrastructure

Security

Should you discover any security issues, please refer to sigstores security process

For container signing, you want cosign