sigstore

Open-source projects categorized as sigstore

Top 7 sigstore Open-Source Projects

  • gitsign

    Keyless Git signing using Sigstore

  • Project mention: Gittuf – a security layer for Git using some concepts introduced by TUF | news.ycombinator.com | 2023-10-24

    > does it also filter/escape ANSI Sequences in messages and author names?

    Not at present! Do you have a link or so I could use to familiarize myself? I'm curious if it'd fall within gittuf's scope.

    > does it block garbage collection?

    Nope, it doesn't. That said, the repository will have more objects, gittuf tracks additional objects through custom refs in `refs/gittuf/`.

    > how do you ensure that the developers are really the developers and there's no spoofing?

    At present, gittuf policies use signing keys. It doesn't rely on the commit metadata for author and committer but rather the commit's signature. We support GPG and Sigstore's gitsign [0] right now, and we want to support other signing mechanisms like SSH keys as well.

    [0] https://github.com/sigstore/gitsign

  • connaisseur

    An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • sigstore-rs

    An experimental Rust crate for sigstore

  • sigstore-the-hard-way

    sigstore the hard way!

  • cosign-keyless-admission-webhook

    Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect

  • sigstore-the-easy-way

    Software signing just got easier

  • go-hello-world

    Demo to showcase how to build a golang application using ko. Sign and push the image to the container registry using https://sigstore.dev. Apply policy controller on Kubernetes to allow only signed images.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

sigstore related posts

  • A toolbox for a secure software supply chain

    1 project | news.ycombinator.com | 26 Aug 2022
  • Enable Gitsign Today and Start Signing your Commits

    2 projects | dev.to | 25 Aug 2022
  • SSH commit verification now supported

    4 projects | news.ycombinator.com | 23 Aug 2022
  • What's everyone working on this week (30/2022)?

    15 projects | /r/rust | 25 Jul 2022
  • sigstore/gitsign: Keyless Git signing using Sigstore

    1 project | /r/devopsish | 24 Jun 2022
  • Keyless Git signing with Sigstore!

    2 projects | /r/kubernetes | 23 Jun 2022
  • Gitsign

    7 projects | news.ycombinator.com | 9 Jun 2022
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 15 May 2024
    Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality. Learn more →

Index

What are some of the best open-source sigstore projects? This list will help you:

Project Stars
1 gitsign 904
2 connaisseur 419
3 sigstore-rs 152
4 sigstore-the-hard-way 109
5 cosign-keyless-admission-webhook 22
6 sigstore-the-easy-way 14
7 go-hello-world 1

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com