Sigstore - Software Artifact Signing and Verification
Transparency Log

Sigstore - Software Artifact Signing and Verification SIGSTORE-2: Transparency Log (Rekor) and Verification

Per Sigstore: Rekor transparency log. Requirements include (a) record signing events to Rekor + (b) verify signatures + Rekor entries + (c) implement verification policy + (d) integrate with consumers.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.