cosign

Code signing and transparency for containers and binaries (by sigstore)

Cosign Alternatives

Similar projects and alternatives to cosign

  1. Poetry

    409 cosign VS Poetry

    Python packaging and dependency management made easy

  2. InfluxDB

    InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.

    InfluxDB logo
  3. speedtest

    Self-hosted Speed Test for HTML5 and more. Easy setup, examples, configurable, mobile friendly. Supports PHP, Node, Multiple servers, and more

  4. OPA (Open Policy Agent)

    Open Policy Agent (OPA) is an open source, general-purpose policy engine.

  5. trivy

    95 cosign VS trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

  6. argo-cd

    Declarative Continuous Deployment for Kubernetes

  7. kubescape

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

  8. checkov

    63 cosign VS checkov

    Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

  9. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  10. grype

    61 cosign VS grype

    A vulnerability scanner for container images and filesystems

  11. falco

    47 cosign VS falco

    Cloud Native Runtime Security

  12. Kyverno

    Cloud Native Policy Management

  13. syft

    39 cosign VS syft

    CLI tool and library for generating a Software Bill of Materials from container images and filesystems

  14. build-push-action

    39 cosign VS build-push-action

    GitHub Action to build and push Docker images with Buildx

  15. rekor

    Software Supply Chain Transparency Log

  16. dependency-track

    Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

  17. metadata-action

    16 cosign VS metadata-action

    GitHub Action to extract metadata (tags, labels) from Git reference and GitHub events for Docker

  18. notation

    A CLI tool to sign and verify artifacts (by notaryproject)

  19. login-action

    13 cosign VS login-action

    GitHub Action to login against a Docker registry

  20. connaisseur

    An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster

  21. in-toto-golang

    A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.

  22. fulcio

    Sigstore OIDC PKI

  23. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better cosign alternative or higher similarity.

cosign discussion

Log in or Post with

cosign reviews and mentions

Posts with mentions or reviews of cosign. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2025-04-16.
  • Introduction to Gitless GitOps: A New OCI-Centric and Secure Architecture
    9 projects | dev.to | 16 Apr 2025
    Flux uses cosign
  • Top Terraform/OpenTofu tools to Use in 2025
    24 projects | dev.to | 4 Feb 2025
    Verifies downloads using cosign and PGP (via gopenpgp), ensuring the integrity and authenticity of tool binaries.
  • 1minDocker #13 - Push, build and dockerize with GitHub Actions
    7 projects | dev.to | 23 Jan 2025
  • 10 Docker Security Best Practices
    6 projects | dev.to | 8 Jan 2025
    SigStore project, including its cosign tool, implements simple signing, storage, and verification of artifacts.
  • Reading the Ruby 3.4 NEWS with professionals (English translation)
    17 projects | dev.to | 26 Dec 2024
    RubyGems now supports sigstore.dev, which aims to improve the security of the software supply chain. Sigstore is a series of mechanisms that provide automated signing for the software supply chain. If you pass the file path to a Sigstore Bundle generated using cosign or sigstore-ruby to --attestation, you can upload the Gem signature to RubyGems.
  • Securing CI/CD Images with Cosign and OPA
    4 projects | dev.to | 15 Nov 2023
    Cosign: In this context, Cosign from the Sigstore project offers a compelling solution. Its simplicity, registry compatibility, and effective link between images and their signatures provide a user-friendly and versatile approach. The integration of Fulcio for certificate management and Rekor for secure logging enhances Cosign's appeal, making it particularly suitable for modern development environments that prioritize security and agility.
  • An Overview of Kubernetes Security Projects at KubeCon Europe 2023
    17 projects | dev.to | 22 May 2023
    sigstore is another suite of tools that focuses on attestation and provenance. Within the suite are two tools I heard mentioned a few times at KubeCon: Cosign and Rekor.
  • Spin 1.0 — The Developer Tool for Serverless WebAssembly
    17 projects | dev.to | 28 Mar 2023
    Since we can distribute Spin applications using popular registry services, we can also take advantage of ecosystem tools such as Sigstore and Cosign, which address the software supply chain issue by signing and verifying applications using Sigstore's new keyless signatures (using OIDC identity tokens from providers such as GitHub).
  • Iron Bank: Secure Registries, Secure Containers
    3 projects | dev.to | 8 Feb 2023
    Use distroless images (which contain only application and its runtime dependencies, and don't include package managers/shells or any other programs you would expect to find in a standard Linux distribution). All distroless images are signed by cosign.
  • Getting hands on with Sigstore Cosign on AWS
    3 projects | dev.to | 31 Jan 2023
    $ COSIGN_EXPERIMENTAL=1 cosign verify-blob --cert https://github.com/sigstore/cosign/releases/download/v1.13.1/cosign-linux-amd64-keyless.pem --signature https://github.com/sigstore/cosign/releases/download/v1.13.1/cosign-linux-amd64-keyless.sig https://github.com/sigstore/cosign/releases/download/v1.13.1/cosign-linux-amd64
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 24 Jun 2025
    InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now. Learn more →

Stats

Basic cosign repo stats
35
5,009
9.5
7 days ago

Sponsored
InfluxDB – Built for High-Performance Time Series Workloads
InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
www.influxdata.com

Did you know that Go is
the 4th most popular programming language
based on number of references?