OpenSSF Project Community
HomePersonasProblemsProjectsPublicationsAbout

Quick Links

Browse by Persona
Software Developer / MaintainerOpen Source Professional (OSPO)Security Engineer / ArchitectCI/CD DevOps & Tooling IntegratorPackage & Repository ManagerExecutive / End-User Consumer
Browse by Problem
Build & Provenance IntegrityArtefact Signing & VerificationDependency & SBOM VisibilityVulnerability ManagementSecure Repository ConfigurationMeasuring Security PosturePolicy & Compliance EnforcementSecrets Management
Browse by Project
Best Practices BadgeBomctlCriticality ScoreFuzz IntrospectorFuzzingBrainGemaragittufGUACin-totoMinderOpenSSF Model Signing (OMS)OpenBaoOpenSSF ScorecardOSS-CRSPackage AnalysisProtobom / SBOM ToolsRepository Service for TUF (RSTUF)SBOMitSecure Agentic FrameworkSigstoreslsa-github-generatorslsa-verifierZarf
Browse by Publication
Gemara Whitepaperin-toto AttestationOSPS BaselineOSV Schema & OpenVEXOSV Record (vulnerability record format)SARIFSoftware Bill of MaterialsSecurity InsightsSLSASLSA ProvenanceVulnerability Exploitability eXchange
About
Problem view

Artefact Signing & Verification

Proving who produced an artefact and confirming it has not been altered in transit, ideally without the burden of managing long-lived signing keys.

Build Integrity Signing Visibility Vulnerabilities Configuration Posture Compliance Secrets

5 OpenSSF projects and publications help with Signing, each with a one-sentence note on how. Prefer another way in? Browse by role →

gittuf

Signs Git metadata and maintains a verifiable reference state log so source history can be authenticated downstream.

Full breakdown

OpenSSF Model Signing (OMS)

Extends identity-based signing and verification to ML models of any format, so consumers can confirm who produced the weights.

Full breakdown

Repository Service for TUF (RSTUF)

Cryptographically signs repository metadata so clients can verify content has not been tampered with in transit.

Full breakdown

SBOMit

Relies on signed attestations over components, so the bill of materials itself becomes cryptographically verifiable.

Full breakdown

Sigstore

Provides keyless, identity-based signing backed by a public transparency log so anyone can verify who built what.

Full breakdown

Personas who care about this

Developer Security DevOps OSPO Package Manager Executive
Pick a different problem Browse all projects
  • OpenSSF contributors
  • operations@openssf.org

Browse OpenSSF projects by the role you play. Every project is mapped to the personas it serves and the problems it solves, with a one-sentence, role-specific usage guide for each.

Copyright © OpenSSF contributors, a Series of LF Projects, LLC. For website terms of use, trademark policy, and other project policies please see https://lfprojects.org. This site is open source. View or contribute at GitHub.