Sigstore - Software Artifact Signing and Verification
Sigstore: Cosign Signing and Storage

Sigstore - Software Artifact Signing and Verification SIGSTORE-COS-1: Keyless Signing

Support identity-based keyless signing using Fulcio certificates and Rekor transparency log by default

Other controls in Sigstore: Cosign Signing and Storage

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.