Sigstore - Software Artifact Signing and Verification
Sigstore: Verification and Policy Enforcement

Sigstore - Software Artifact Signing and Verification SIGSTORE-VER-1: Timestamp Verification

Verify signed timestamp in bundle ensuring it falls within certificate issuance time window

Other controls in Sigstore: Verification and Policy Enforcement

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.