Gitsign
Signs Git commits and tags with Sigstore keyless signing, requiring no GPG key.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Sigstore | signs |
- Interfaces
cli- Install
-
brew
gitsigngogithub.com/sigstore/gitsign - Emits
- signature
- Runtime
- Needs network Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Increasingly relevant as agents commit code: signing answers "who or what produced this change" in a way an author field cannot.
- Website
- https://github.com/sigstore/gitsign
- Repository
- https://github.com/sigstore/gitsign
- License
- Apache-2.0 — read from the repository's LICENSE file, verified 2026-09-17
- Stars
- 1126 · last commit 2026-09-14
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.