Code-signing for npm packages
☆178Mar 2, 2026Updated this week
Alternatives and similar repositories for sigstore-js
Users that are interested in sigstore-js are comparing it to the libraries listed below
Sorting:
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆75Updated this week
- A collection of reusable Github Actions workflows.☆159Updated this week
- General sigstore community repo☆44Feb 27, 2026Updated last week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆73Updated this week
- Helm charts for sigstore project☆90Updated this week
- A reading list for software supply-chain security.☆365Nov 21, 2022Updated 3 years ago
- Build and deploy Go applications with Terraform☆30Updated this week
- java clients for sigstore☆74Updated this week
- Keyless Git signing using Sigstore☆1,066Updated this week
- Go library for Sigstore signing and verification☆84Feb 23, 2026Updated last week
- Sigstore OIDC PKI☆810Updated this week
- OpenCP shim is a simple HTTP server that implements the Kubernetes API server interface. It is a shim that allows you to use the Kubernet…☆14Mar 16, 2023Updated 2 years ago
- Keyless Git signing with cosign!☆11May 12, 2022Updated 3 years ago
- TUF repository for Sigstore trust root☆120Updated this week
- Plugin for Helm to integrate the sigstore ecosystem☆68Feb 27, 2026Updated last week
- Search Rekor for entries☆39Updated this week
- Build OCI images from APK packages directly without Dockerfile☆1,560Updated this week
- Dynamic GitHub Actions from Wolfi packages☆44May 15, 2025Updated 9 months ago
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- native go library for installation and management of apk packages☆32Jun 5, 2024Updated last year
- JavaScript implementation of The Update Framework (TUF)☆81Feb 23, 2026Updated last week
- Code signing and transparency for containers and binaries☆5,700Updated this week
- Common go library shared across sigstore services and clients☆502Updated this week
- An awesome open source Survey Management System.☆17Mar 20, 2024Updated last year
- Software Supply Chain Transparency Log☆1,092Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifests☆443Feb 26, 2026Updated last week
- Free 0-CVE Images☆34Jul 10, 2024Updated last year
- Supply Chain Security in Tekton Pipelines☆270Updated this week
- build APKs from source code☆577Updated this week
- nginx image demo☆19Sep 11, 2023Updated 2 years ago
- sigstore the hard way!☆118Aug 6, 2025Updated 7 months ago
- Transparenty Immutable Container Image Tags☆20Jul 5, 2023Updated 2 years ago
- Lambda function for verifying signed images in ECS☆37Mar 9, 2024Updated last year
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42May 11, 2023Updated 2 years ago
- Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations☆59Updated this week
- Sigstore user stories☆31Aug 25, 2023Updated 2 years ago
- ☆58Jun 1, 2022Updated 3 years ago
- Container image registry that serves images built fresh when you ask for them☆238Feb 14, 2025Updated last year
- ☆29Feb 4, 2026Updated last month