Sigstore - Software Artifact Signing and Verification
Sigstore: Cosign Signing and Storage

Sigstore - Software Artifact Signing and Verification SIGSTORE-COS-2: Key-Based Signing

Support signing with hardware tokens, KMS systems, or cosign-generated encrypted key pairs

Other controls in Sigstore: Cosign Signing and Storage

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.