implementing-sigstore-for-software-signing

mukul975/implementing-sigstore-for-software-signing · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Signs and verifies software artifacts using Sigstore's keyless signing, Rekor transparency log, and Fulcio certificate authority, integrating into CI/CD pipelines and Kubernetes admission controls.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 5.1 KB
  • 📁scripts
  • ⚙️agent.py 17.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. verifying-build-provenance-with-slsa-sigstore · mukul975 bundle
    Verify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.
    24.6k
    repo stars
  2. implementing-code-signing-for-artifacts · mukul975 bundle
    Sign build artifacts (binaries, packages, containers) with GPG, Sigstore, and platform-specific tools to ensure integrity and authenticity throughout the software supply chain.
    24.6k
    repo stars
  3. implementing-image-provenance-verification-with-cosign · mukul975 bundle
    Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
    24.6k
    repo stars
  4. github-actions-hardening · github bundle
    Reviews and hardens GitHub Actions workflows against injection, privilege escalation, supply-chain, and token-scoping risks that pattern matchers miss.
    36.2k
    repo stars
  5. securing-container-registry-images · mukul975 bundle
    Scan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
    24.6k
    repo stars
  6. securing-container-registry-with-harbor · mukul975 bundle
    Configure and manage Harbor container registry with security features including vulnerability scanning, image signing, RBAC, content trust, and audit logging.
    24.6k
    repo stars

Frequently asked questions

How do I install the implementing-sigstore-for-software-signing skill?

Run npx skillmds add mukul975/implementing-sigstore-for-software-signing in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-sigstore-for-software-signing skill do?

Signs and verifies software artifacts using Sigstore's keyless signing, Rekor transparency log, and Fulcio certificate authority, integrating into CI/CD pipelines and Kubernetes admission controls. It is listed under Security, DevOps & Infra, CI/CD, Secure Coding on SkillMD.

Is implementing-sigstore-for-software-signing safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-sigstore-for-software-signing?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-sigstore-for-software-signing free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-sigstore-for-software-signing?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.