Gitsign
Radar: Initial
Apache-2.0
Signs Git commits and tags with Sigstore keyless signing, requiring no GPG key.
Sigstore
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Sigstore | signs |
Using this from an agent
- Interfaces
cli- Install
-
brew
gitsigngogithub.com/sigstore/gitsign - Emits
- signature
- Runtime
- Needs network Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Sign commits without the GPG key management that stops most teams from signing at all.
coding-agenthuman
Establish which identity authored a commit, when an agent may be the one committing.
coding-agent
Increasingly relevant as agents commit code: signing answers "who or what produced this change" in a way an author field cannot.
- Website
- https://github.com/sigstore/gitsign
- Repository
- https://github.com/sigstore/gitsign
- License
- Apache-2.0 — read from the repository's LICENSE file, verified 2026-08-11
- Stars
- 1115 · last commit 2026-08-10
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.