awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Outils de signature et de vérification d'artefacts logiciels

Classement mis à jour le 30 juin 2026

For un toolkit de signature d'artefacts, the strongest matches are sigstore/cosign (Cosign is a dedicated tool for cryptographically signing and), containers/skopeo (Skopeo is a container image management tool that includes) and notaryproject/notary (Notary uses cryptographic signing and verification via The Update). Each is ranked by relevance to your query, popularity and recent activity.

Outils et frameworks de signature cryptographique d'artefacts logiciels pour garantir l'intégrité et la confiance dans la supply chain.

Outils de signature et de vérification d'artefacts logiciels

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • sigstore/cosignAvatar de sigstore

    sigstore/cosign

    5,667Voir sur GitHub↗

    Cosign is a tool for signing and verifying software artifacts, primarily those stored in OCI-compatible registries such as container images, Helm charts, SBOMs, and Tekton bundles. It supports keyless signing using ephemeral keys and short-lived certificates from the Sigstore public-good infrastructure, associating signatures with an OpenID Connect identity rather than a long-lived cryptographic key. The project provides multiple signing and verification methods, including private keys, key pairs stored in KMS providers like AWS KMS and Azure Key Vault, and hardware security keys. It can sign

    Cosign is a dedicated tool for cryptographically signing and verifying software artifacts, with first-class support for OCI containers, keyless and key-based signing, attestations (SBOM, in-toto), and CI/CD integration, making it a flagship match for supply chain artifact signing and verification.

    GoArtifact Signing OperationsContainer Image SigningIn-Toto Attestation Attachments
    Voir sur GitHub↗5,667
  • containers/skopeoAvatar de containers

    containers/skopeo

    10,982Voir sur GitHub↗

    Skopeo is an OCI container image manager and registry client designed for inspecting, copying, and signing container images across different registries and storage backends. It enables the manipulation of container images using direct API calls to registries, operating independently of a local container daemon or runtime. The tool provides specialized capabilities for container image mirroring and synchronization, specifically supporting the mirroring of external repositories to internal registries for air-gapped environments. It also functions as a container image signing tool, allowing for

    Skopeo is a container image management tool that includes signing and verification of OCI images, which directly addresses the intent for container artifact signing, but its focus on containers means it does not natively handle binaries or packages or provide full attestation and policy features.

    GoContainer Image SigningContainer Image Signing Tools
    Voir sur GitHub↗10,982
  • notaryproject/notaryAvatar de notaryproject

    notaryproject/notary

    3,287Voir sur GitHub↗

    Notary is a project that allows anyone to have trust over arbitrary collections of data

    Notary uses cryptographic signing and verification via The Update Framework to secure container images and arbitrary data, directly addressing the need for artifact integrity and provenance in the software supply chain, though its attestation support is limited.

    GoContainer Security
    Voir sur GitHub↗3,287

Related searches

  • toolkit de preuves à divulgation nulle de connaissance
  • bibliothèque de cryptographie en Rust
  • bibliothèque de cryptographie post-quantique
  • a cryptographic library for Go applications
  • outil de chiffrement des secrets git
  • coffre-fort de secrets auto-hébergé
  • un outil de génération de SBOM
  • a cryptography library written in Go or Rust