cosign

Code signing and transparency for containers and binaries (by sigstore)

Cosign Alternatives

Similar projects and alternatives to cosign

  1. Poetry

    417 cosign VS Poetry

    Python packaging and dependency management made easy

  2. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  3. speedtest

    125 cosign VS speedtest

    Self-hosted Speed Test for HTML5 and more. Easy setup, examples, configurable, mobile friendly. Supports PHP, Node, Multiple servers, and more

  4. trivy

    120 cosign VS trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

  5. OPA (Open Policy Agent)

    Open Policy Agent (OPA) is an open source, general-purpose policy engine.

  6. argo-cd

    Declarative Continuous Deployment for Kubernetes

  7. kubescape

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

  8. checkov

    72 cosign VS checkov

    Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

  9. grype

    64 cosign VS grype

    A vulnerability scanner for container images and filesystems

  10. falco

    55 cosign VS falco

    Cloud Native Runtime Security

  11. Kyverno

    Unified Policy as Code

  12. syft

    42 cosign VS syft

    CLI tool and library for generating a Software Bill of Materials from container images and filesystems

  13. build-push-action

    39 cosign VS build-push-action

    GitHub Action to build and push Docker images with Buildx

  14. rekor

    34 cosign VS rekor

    Software Supply Chain Transparency Log

  15. metadata-action

    16 cosign VS metadata-action

    GitHub Action to extract metadata (tags, labels) from Git reference and GitHub events for Docker

  16. notation

    A CLI tool to sign and verify artifacts (by notaryproject)

  17. login-action

    13 cosign VS login-action

    GitHub Action to login against a Docker registry

  18. in-toto-golang

    A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.

  19. spire

    6 cosign VS spire

    The SPIFFE Runtime Environment

  20. fulcio

    Sigstore OIDC PKI

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better cosign alternative or higher similarity.

cosign discussion

Log in or Post with

cosign reviews and mentions

Posts with mentions or reviews of cosign. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2026-03-20.

Stats

Basic cosign repo stats
36
6,036
9.6
2 days ago

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com

Did you know that Go is
the 4th most popular programming language
based on number of references?