{"data":{"slug":"cosign","name":"Cosign","tagline":"Apache-2.0 Sigstore keyless container/artifact signing CLI","category":"devops","categoryName":"DevOps","url":"https://docs.sigstore.dev/cosign/signing/overview/","github":"https://github.com/sigstore/cosign","pricing":"open-source","hook":"Cosign is keyless OCI signing when long-lived Notary keys are the supply-chain liability.","whatsGood":"Apache-2.0. Sign/verify containers and blobs; store signatures beside digests in the registry. Keyless via Fulcio OIDC + Rekor transparency log. Also key-pair/KMS. CI-native cosign sign/verify.","theCatch":"Signing CLI + public-good Sigstore infra — not a full policy admission controller (pair with Kyverno/OPA). Offline/air-gap needs different PKI. Registry must support referrers/OCI artifacts cleanly.","verdict":"Apache-2.0 Sigstore signing. Free CLI; policy engines are separate.","addedAt":"2026-09-04","featured":false,"domain":"DevOps","subSpecialty":"Security","capabilities":["signing","supply-chain","cli"],"surfaces":["CLI","Self-host"],"ecosystem":["Multi-platform","Go"],"licenseModel":"Apache-2.0","githubStars":6279},"related":[{"slug":"github-actions","name":"GitHub Actions","tagline":"CI/CD that lives where your code does"},{"slug":"docker","name":"Docker","tagline":"Container runtime that changed deployment"},{"slug":"kubernetes","name":"Kubernetes","tagline":"Container orchestration at scale"},{"slug":"terraform","name":"Terraform","tagline":"Infrastructure as code that actually works"},{"slug":"pulumi","name":"Pulumi","tagline":"Infrastructure as code in real languages"}],"links":{"self":"/api/gems/cosign","html":"/gems/cosign","markdown":"/gems/cosign.md","category":"/api/gems?category=devops","categoryPage":"/stacks/devops"}}