Code-signing for npm packages
☆181Aug 17, 2026Updated last week
Alternatives and similar repositories for sigstore-js
Users that are interested in sigstore-js are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Migration CLI for Azure DevOps to GitHub migrations☆23Aug 13, 2026Updated last week
- General sigstore community repo☆45Updated this week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆87Updated this week
- ☆20Jul 23, 2026Updated last month
- Build OCI images from APK packages directly without Dockerfile☆1,667Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Common go library shared across sigstore services and clients☆535Updated this week
- java clients for sigstore☆78Updated this week
- Helm charts for sigstore project☆92Updated this week
- Plugin for Helm to integrate the sigstore ecosystem☆71Jul 25, 2026Updated last month
- Build and deploy Go applications with Terraform☆31Aug 7, 2026Updated 2 weeks ago
- Resources to help vulnerability scanners☆14Updated this week
- Search Rekor for entries☆47Mar 23, 2026Updated 5 months ago
- JavaScript implementation of The Update Framework (TUF)☆83Aug 17, 2026Updated last week
- Supply Chain Security in Tekton Pipelines☆275Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Sigstore user stories☆32Aug 25, 2023Updated 2 years ago
- Code signing and transparency for containers and binaries☆6,228Updated this week
- ☆14May 10, 2019Updated 7 years ago
- Go library for Sigstore signing and verification☆92Aug 17, 2026Updated last week
- Adversary emulation for EDR/SIEM testing (macOS/Linux)☆54Jun 8, 2026Updated 2 months ago
- Free 0-CVE Images☆34Jul 10, 2024Updated 2 years ago
- 🔮 ✈️ to integrate OPA Gatekeeper's new ExternalData feature with cosign to determine whether the images are valid by verifying their sig…☆79Dec 4, 2025Updated 8 months ago
- sigstore the hard way!☆120May 29, 2026Updated 2 months ago
- A utility to generate SPDX-compliant Bill of Materials manifests☆466Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Sample education demos for Chainguard Images☆15Jun 23, 2026Updated 2 months ago
- Comparison of Chainguard Images to others☆21Updated this week
- OpenCP shim is a simple HTTP server that implements the Kubernetes API server interface. It is a shim that allows you to use the Kubernet…☆15Mar 16, 2023Updated 3 years ago
- Interfaces and implementations for building Kubernetes releases.☆20Updated this week
- native go library for installation and management of apk packages☆31Jun 5, 2024Updated 2 years ago
- ☆34Jun 26, 2026Updated last month
- #supply #chain #attack #detection☆675Updated this week
- Lambda function for verifying signed images in ECS☆39Mar 9, 2024Updated 2 years ago
- 🔍 Rekor transparency log monitoring and alerting☆27Oct 2, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Frogger-style terminal game that visualizes container vulnerabilities discovered by Grype☆19Dec 8, 2025Updated 8 months ago
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆61Aug 1, 2026Updated 3 weeks ago
- Container image registry that serves images built fresh when you ask for them☆245Aug 9, 2026Updated 2 weeks ago
- kubectl plugin for signing Kubernetes manifest YAML files with sigstore☆89Jul 31, 2026Updated 3 weeks ago
- An Action for printing OIDC claims in GitHub Actions.☆119Sep 22, 2025Updated 11 months ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆44May 11, 2023Updated 3 years ago
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago