Sigstore Cosign

Sigstore — keyless signing for software artifacts using OIDC identities and short-lived certificates from Fulcio CA, with Rekor transparency log. Cosign is the CLI for signing/verifying containers, OCI artifacts, blobs, and attestations (SBOMs, provenance). Covers GitHub Actions OIDC integration, policy enforcement (cosign-policy-controller, Kyverno), Notary v2 vs Cosign, and supply-chain attestation patterns (SLSA). USE WHEN: user mentions "Sigstore", "Cosign", "Fulcio", "Rekor", "keyless signing", "OIDC signing", "cosign sign", "cosign verify", "SLSA provenance", "OCI artifact signing", "attestation cosign" DO NOT USE FOR: GPG-style signing - use GPG-specific docs DO NOT USE FOR: Code signing certificates (Apple Developer ID, Authenticode) - platform-specific DO NOT USE FOR: Reproducible builds spec - use `infrastructure/reproducible-builds`

claude-dev-suite Updated 28 repo stars

File contents

claude-dev-suite/claude-dev-suite/tree/main/skills/security/sigstore-cosign commit c3b077f67f

Frequently asked questions

npx skillmds@latest add claude-dev-suite/sigstore-cosign