{"request_id":"req_01M49249DPMA0V2P2HM6XPC1JE","technology":{"canonical_id":"tech_000000000000009YBMQKPCDYMV","parent_canonical_id":"","parent_id_zoho":"","name":"Sigstore","slug":"sigstore","requires_context":false,"popularity":null,"description":"Framework and services for signing software artifacts, verifying signer identity and auditing signing events.","explanation":"Sigstore combines signing clients with certificate and transparency-log infrastructure. Cosign signs and verifies artifacts; Fulcio binds short-lived certificates to identities; Rekor records signing information. These components can work together or independently. Sigstore is a concrete software framework and public service ecosystem, not a generic name for artifact signing.","official_website_url":"https://www.sigstore.dev/","official_documentation_url":"https://docs.sigstore.dev/","use_cases":[{"statement":"Audit signing events through a transparency log.","evidence_urls":["https://docs.sigstore.dev/about/tooling/"]},{"statement":"Sign and verify release artifacts, container images and SBOMs.","evidence_urls":["https://docs.sigstore.dev/"]}],"strengths":[{"statement":"Clients can use a hosted public deployment or independently configured trust infrastructure.","evidence_urls":["https://docs.sigstore.dev/cosign/system_config/custom_components/","https://docs.sigstore.dev/cosign/system_config/public_deployment/"]},{"statement":"Identity-based signing uses short-lived certificates and ephemeral keys, reducing the need for long-lived signing-key management.","evidence_urls":["https://docs.sigstore.dev/about/security/"]}],"limitations":[{"statement":"Compromised identity providers or certificate-authority services can produce unauthorized certificates; detection depends on monitoring transparency logs.","evidence_urls":["https://docs.sigstore.dev/about/security/"]},{"statement":"Verification must check the expected signer identity and issuer as well as cryptographic validity; a valid signature alone is not an assurance that software is safe.","evidence_urls":["https://docs.sigstore.dev/","https://docs.sigstore.dev/about/the-importance-of-verification/"]}],"pricing":{"access_model":"unknown","billing_models":[],"free_trial_availability":"unknown","evidence_urls":[]},"technology_license":{"name":"Apache License 2.0","scope":"Core Cosign, Fulcio and Rekor component source repositories only; other repositories and hosted-service terms require separate inspection.","spdx_id":"Apache-2.0","evidence_urls":["https://raw.githubusercontent.com/sigstore/cosign/main/LICENSE","https://raw.githubusercontent.com/sigstore/fulcio/main/LICENSE","https://raw.githubusercontent.com/sigstore/rekor/main/LICENSE"]},"organizations":[{"name":"Open Source Security Foundation (OpenSSF)","role":"foundation","evidence_urls":["https://docs.sigstore.dev/"]},{"name":"Sigstore community","role":"maintainer","evidence_urls":["https://docs.sigstore.dev/"]}],"certifications":null,"deployment_options":[{"type":"managed_service","scope":"Sigstore public-good signing infrastructure used by clients.","evidence_urls":["https://docs.sigstore.dev/","https://docs.sigstore.dev/cosign/system_config/public_deployment/"]},{"type":"self_hosted","scope":"Operate custom Sigstore components and roots of trust.","evidence_urls":["https://docs.sigstore.dev/cosign/system_config/custom_components/"]}],"lifecycle":"active","revision":1,"updated_at":"2026-10-04T17:19:30.645463Z","reviewed_at":"2026-10-04T17:19:30.645463Z","source_freshness_at":"2026-10-04T14:57:06Z","aliases":null,"category_ids":["cat_11MNQ7PJNS8D3T72QD5C0G1F6Y"],"domain_ids":["dom_1D2B1EQWZC9G38JXH4C7REEMPK"],"classification_kind":"framework","sources":[{"url":"https://docs.sigstore.dev/","type":"official","title":"Sigstore overview","claim":"Artifact-signing purpose, verification steps, community/OpenSSF ownership and explicit free public-good access statement.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://docs.sigstore.dev/about/doc_locations/","type":"official","title":"Sigstore documentation locations","claim":"Identifies official docs and project website.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://docs.sigstore.dev/about/security/","type":"official","title":"Sigstore security model","claim":"OIDC identity, short-lived keys and monitoring-dependent compromise detection.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://docs.sigstore.dev/about/the-importance-of-verification/","type":"official","title":"The importance of verification","claim":"Trust-policy verification and the limits of signing.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://docs.sigstore.dev/about/tooling/","type":"official","title":"Sigstore tooling","claim":"Cosign, Fulcio and Rekor roles and independent/composed operation.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://docs.sigstore.dev/cosign/system_config/custom_components/","type":"official","title":"Configuring custom Sigstore components","claim":"Independent component endpoints and custom trust infrastructure.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://docs.sigstore.dev/cosign/system_config/public_deployment/","type":"official","title":"Sigstore public deployment","claim":"Hosted public deployment and trust configuration.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://github.com/sigstore","type":"official","title":"Sigstore GitHub organization","claim":"Project distributed across multiple component source repositories; not a single umbrella source repository.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://raw.githubusercontent.com/sigstore/cosign/main/LICENSE","type":"official","title":"Cosign LICENSE","claim":"Apache License 2.0 applies to this core component source.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://raw.githubusercontent.com/sigstore/fulcio/main/LICENSE","type":"official","title":"Fulcio LICENSE","claim":"Apache License 2.0 applies to this core component source.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://raw.githubusercontent.com/sigstore/rekor/main/LICENSE","type":"official","title":"Rekor LICENSE","claim":"Apache License 2.0 applies to this core component source.","retrieved_at":"2026-10-04T14:57:06Z"},{"url":"https://www.sigstore.dev/","type":"official","title":"Sigstore homepage","claim":"Official project homepage as identified by its documentation-location page.","retrieved_at":"2026-10-04T14:57:06Z"}],"external_ids":[{"system":"beast","value":"358446000127802011"}],"provenance":"Published taxonomy release 2026.10.7"},"release_version":"2026.10.7"}
