OK to import cosign-3.1.2?

Comment:
sigstore signing tool

Description:
Signing OCI containers (and other artifacts) using Sigstore.

Cosign supports:

- "Keyless signing" with the Sigstore public good Fulcio certificate authority
  and Rekor transparency log (default)
- Hardware and KMS signing
- Signing with a cosign generated encrypted private/public keypair
- Container Signing, Verification and Storage in an OCI registry
- Bring-your-own PKI

Maintainer: Rafael Sadowski <[email protected]>

WWW: https://www.sigstore.dev/


Reply via email to