sigstore-signing

Solid

Sign container images and artifacts with cosign (keyless via OIDC and key-based); verify signatures in CD pipelines and admission policies.

AI & Automation 14 stars 3 forks Updated 3 days ago MIT

Install

View on GitHub

Quality Score: 86/100

Stars 20%
39
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Skill: Sigstore / cosign Signing > **Expertise:** cosign keyless signing (Sigstore), key-based signing, signature verification, Kyverno/OPA enforcement, Rekor transparency log. ## When to load When setting up image signing in CI, verifying signatures before deploy, or enforcing signature policies in K8s admission. ## Keyless Signing (OIDC — GitHub Actions) ```yaml # .github/workflows/sign.yml jobs: sign: runs-on: ubuntu-latest permissions: contents: read packages: write id-token: write # ← required for keyless OIDC signing steps: - name: Install cosign uses: sigstore/cosign-installer@v3 - name: Build and push id: build uses: docker/build-push-action@v6 with: push: true tags: ghcr.io/myorg/order-service:${{ github.sha }} - name: Sign image (keyless) run: | cosign sign \ --yes \ ghcr.io/myorg/order-service@${{ steps.build.outputs.digest }} # Signature stored in Rekor transparency log # No private key needed — OIDC token proves identity ``` ## Key-Based Signing (when OIDC not available) ```bash # Generate signing key pair (do once; store private key in Vault) cosign generate-key-pair # Creates: cosign.key (private — store in Vault) + cosign.pub (public — commit to repo) # Sign with key cosign sign \ --key cosign.key \ registry.example.com/myorg/order-service:v1.2.3 # Sign in CI using secret cosign...

Details

Author
sawrus
Repository
sawrus/agent-guides
Created
3 months ago
Last Updated
3 days ago
Language
Shell
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

implementing-image-provenance-verification-with-cosign

Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.

12,642 Updated today
mukul975
AI & Automation Featured

implementing-sigstore-for-software-signing

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain signing, keyless container signing, Sigstore deployment, or artifact provenance verification.

12,642 Updated today
mukul975
AI & Automation Featured

implementing-code-signing-for-artifacts

This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines.

12,642 Updated today
mukul975
AI & Automation Solid

pipeline-security

Secure CI/CD pipelines with keyless signing, OIDC federation, provenance attestations, policy enforcement, and hardened runners.

14 Updated 3 days ago
sawrus
AI & Automation Solid

windows-authenticode-signer

Sign Windows executables with Authenticode using signtool, supporting EV and standard certificates

1,034 Updated today
a5c-ai