Skip to main content
FOSSA Logo

Sigstore

An open-source project providing a standard way to sign, verify, and protect software artifacts without managing long-term cryptographic keys.

See your software supply chain in full

FOSSA maps every open source dependency, license, and vulnerability across your codebase, so the terms on this page become findings you can act on.