Stack Gems
Menu
← Catalog

Cosign

Apache-2.0 Sigstore keyless container/artifact signing CLI

DevOps / Security · Apache-2.0 · 6.3k

What's Good

Apache-2.0. Sign/verify containers and blobs; store signatures beside digests in the registry. Keyless via Fulcio OIDC + Rekor transparency log. Also key-pair/KMS. CI-native cosign sign/verify.

The Catch

Signing CLI + public-good Sigstore infra — not a full policy admission controller (pair with Kyverno/OPA). Offline/air-gap needs different PKI. Registry must support referrers/OCI artifacts cleanly.

Verdict

Apache-2.0 Sigstore signing. Free CLI; policy engines are separate.

Embed

Reviewed on Stack Gems
[![Reviewed on Stack Gems](https://stackgems.com/badge/cosign.svg)](https://stackgems.com/gems/cosign)

Related

DevOps