Sigstore - Software Artifact Signing and Verification
Keyless Signing

Sigstore - Software Artifact Signing and Verification SIGSTORE-1: Keyless Signing with Short-Lived Certificates

Per Sigstore: keyless signing. Requirements include (a) Keyless Signing With Short-Lived Certificates via Fulcio + (b) OIDC identity-based signing + (c) Certificate Transparency Monitoring + (d) Reusable Workflow and Pipeline Hardening + (e) maintain Sigstore client integration.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.