OpenSSF project

Sigstore

A free, identity-based artefact-signing service backed by a public transparency log so anyone can verify who built what.

How each persona uses Sigstore

Software Developer / Maintainer Developer

Adopts Sigstore to cryptographically sign artifacts and ensure their integrity early in the release process.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Standardizes on keyless signing (Sigstore) across the enterprise to eliminate the overhead of managing long-lived cryptographic keys.

See everything for OSPO →

Security Engineer / Architect Security

Validates the transparency log to audit the provenance and authenticity of software components used in production.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Deploys Sigstore to enable identity-based (keyless) signing via OIDC, eliminating the risk of compromised long-lived build secrets and automating artifact verification in the pipeline.

See everything for DevOps →

Package & Repository Manager Package Manager

Integrates Sigstore natively into the package registry to automatically verify incoming artifact signatures and display provenance to users.

See everything for Package Manager →

Executive / End-User Consumer Executive

Verifies cryptographic signatures as trust signals to confirm artifact integrity post-release.

See everything for Executive →

Problems Sigstore helps with

Artefact Signing & Verification Signing

Provides keyless, identity-based signing backed by a public transparency log so anyone can verify who built what.

See everything for Signing →

Build & Provenance Integrity Build Integrity

Records signatures in a transparency log, making artefact provenance independently auditable downstream.

See everything for Build Integrity →