HTTP/2 200
date: Fri, 26 Dec 2025 10:49:09 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"4d98efc4e9d99bfe6601452d9cefc881"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com/ copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=UdAGadH44bbJ7sNVY%2FZXdixCHWUQUSNothYe1SQ2e6WS89xmxp8jxSDH6mSaRGCQvTw2NbwWrBJQk1gsN4okwJdOgElio7MsmyhUXgTuK0yTS%2FgRxxAcdrUBS1KcDfWLAEMzMrJV3g9aNxhf5D%2FlbRDJkzEq6XL1vVpTf3E1ZOfZusKOvfs4f%2FBaP4HQLZgZBJ1L237gKlcc4ZStwjP7g2Vj%2F3WkEkd0INup086%2FKK7unxDNE2OCr1B3cxmXBNE29RXXyDROnGOmWE3djGfQ2w%3D%3D--Jl%2Bb%2B%2BNwJiBYebqz--uFnRz0Q7k86vKQR83Lm2eg%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.1443769703.1766746148; Path=/; Domain=github.com; Expires=Sat, 26 Dec 2026 10:49:08 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Sat, 26 Dec 2026 10:49:08 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: BE3C:2D8E00:36AFD78:4186F5F:694E6824
sigstore · GitHub
sigstore
Software Supply Chain Security
Verified
We've verified that the organization sigstore controls the domain:
Sign. Verify. Protect. Making sure your software is what it claims to be.
Learn more at https://sigstore.dev/
Pinned
Loading
Code signing and transparency for containers and binaries
Go
5.5k
676
Software Supply Chain Transparency Log
Go
1k
193
An experimental Rust crate for sigstore
Rust
219
70
A Sigstore client written in Python
Python
303
66
java clients for sigstore
Java
71
25
Repositories
Showing 10 of 65 repositories
scaffolding
Public
Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.
sigstore/scaffolding’s past year of commit activity
Go
70
Apache-2.0
63
9
6
Updated Dec 26, 2025
sigstore/root-signing’s past year of commit activity
Makefile
117
Apache-2.0
88
20
2
Updated Dec 26, 2025
sigstore/gh-action-sigstore-python’s past year of commit activity
Python
62
Apache-2.0
14
11
0
Updated Dec 25, 2025
sigstore/root-signing-staging’s past year of commit activity
10
Apache-2.0
10
7
0
Updated Dec 25, 2025
helm-sigstore
Public
Plugin for Helm to integrate the sigstore ecosystem
sigstore/helm-sigstore’s past year of commit activity
Go
67
Apache-2.0
14
2
2
Updated Dec 25, 2025
sigstore/timestamp-authority’s past year of commit activity
Go
110
Apache-2.0
50
3
2
Updated Dec 25, 2025
sigstore/sigstore-probers’s past year of commit activity
rekor-monitor
Public
Log monitor for Rekor to verify immutability and monitor entries
sigstore/rekor-monitor’s past year of commit activity
Go
42
Apache-2.0
33
11
3
Updated Dec 24, 2025
sigstore/terraform-modules’s past year of commit activity
HCL
4
Apache-2.0
7
1
1
Updated Dec 23, 2025
sigstore/github-sync’s past year of commit activity
Go
6
Apache-2.0
4
0
0
Updated Dec 23, 2025
You can’t perform that action at this time.