Cosign
Signs and verifies containers, blobs and SBOMs with keyless signing backed by OIDC identity and a public transparency log — no long-lived signing key to manage or lose.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Sigstore | signsalso verifies |
The entry point — keyless signing and verification of containers and blobs. |
- Interfaces
clilibraryci-action- Install
-
brew
cosigngogithub.com/sigstore/cosign/v2/cmd/cosign - Invoke
cosign verify <registry>/<image>:<tag> --certificate-identity <identity> --certificate-oidc-issuer <issuer>- Consumes
- oci-image, filesystem, spdx
- Emits
- json, signature
- Runtime
- Needs network Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
`verify` requires naming the expected identity and issuer. A verification that does not pin those checks only that SOMEBODY signed it — which is not a security property.
- Website
- https://github.com/sigstore/cosign
- Repository
- https://github.com/sigstore/cosign
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 6310 · last commit 2026-09-15
- Matching caveat
- The name is an ordinary English word, so the job-corpus matcher cannot use it — sampled matches were "co-sign", which appears in lending and finance postings. The bare name is blocked in the matcher, so this count reflects only qualified matches. Real adoption needs another source.
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.