Softwr
Cosign logo

Cosign

Signs and verifies container images and artifacts, with or without managing keys

As of 31 August 2026, Cosign is free to use. The Sigstore signing client. Softwr lists it under Cybersecurity. Cosign is made by Sigstore, under the Open Source Security Foundation, available on macOS, Linux, Windows, Docker.

Overview

What Cosign does

Cosign signs container images, blobs and arbitrary artifacts, storing signatures in the OCI registry beside the thing they sign. It supports keyless signing through Sigstore, where a short-lived certificate is issued against an OIDC identity and recorded in a public transparency log, as well as self-managed keys, cloud key management services and hardware tokens. It can attach in-toto attestations, including a bill of materials produced elsewhere. The boundary is worth stating plainly because the marketing around supply chain security blurs it. Cosign attests authorship and integrity. It has no vulnerability knowledge at all: it does not enumerate CVEs, it does not analyse reachability, and while it can carry an SBOM as a signed attestation it never reads what that attestation says. A signature proves an identity signed this artifact. It does not prove the artifact is safe, and it does not prove that identity was entitled to sign it. It also enforces nothing by itself. Verification is a command somebody runs. Turning that into a control that stops an unsigned image from running requires a separate admission controller, and a bare verify command without a pinned certificate identity and issuer accepts a signature from anyone at all, which is close to worthless.

What people use it for

  • Signing container images in a build pipeline without managing long-lived private keys
  • Attaching a signed bill of materials to a release so consumers can verify its provenance
  • Meeting a customer or regulatory requirement for signed artifacts
  • Verifying third-party images before they enter an internal registry

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Cosign.

  • Keyless signing inherits every weakness of the identity provider behind it. Sigstore’s own threat model states that if an identity provider is compromised, Sigstore will issue certificates to those identities, so a compromised account produces perfectly valid signatures.
  • A signature proves who signed, never whether they should have. The documentation is explicit that Sigstore cannot determine authorisation, so every consumer must write and maintain their own identity and issuer policy or verification means nothing.
  • Nothing is enforced without an admission controller. Signing changes what you can prove, not what runs, and the official policy controller has a small maintainer base for a component sitting in a cluster admission path.
  • Upgrades break pipelines. Version 3 changed defaults, version 4 is announced as removing legacy functionality and roughly half the command line flags, and two official client libraries still lacked support for the new log format as of mid 2026.
  • Signatures do not expire. An artifact signed before a maintainer account was compromised and one signed after are indistinguishable unless somebody is actively monitoring the transparency log, and almost nobody is.

Cross-shopped

What people choose instead of Cosign

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

  • Cosign logo
    Cosign
    vs
    Sigstore logo
    Sigstore

    Sigstore: The wider project, if the question is the infrastructure rather than the client

  • Cosign logo
    Cosign
    vs
    Syft logo
    Syft

    Syft: A different job entirely: what is inside the artifact rather than who signed it

Pricing

What Cosign costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Cosign

Free

  • Apache-2.0
  • Public Sigstore infrastructure free to use
  • No usage limits published
  • Community support only

Capabilities

Features

  • Keyless signing

    Short-lived certificates issued against an OIDC identity, with no key material to store

  • Key and KMS signing

    Self-managed keys, AWS, Google, Azure and Vault key management, and PKCS#11 hardware tokens

  • Registry-native storage

    Signatures live in the OCI registry alongside the artifact

  • In-toto attestations

    Attaches signed provenance and bill of materials documents

  • Offline verification

    Verification without contacting the transparency log, added in version 3

  • Trusted root and signing config

    Key and log rotation without requiring every client to upgrade

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Does Cosign tell me if an image is vulnerable?

No. It has no vulnerability knowledge whatsoever. It can carry an SBOM as a signed attestation but never reads it. Pair it with a scanner.

Is signing alone enough?

No. Verification is a command somebody runs. Without an admission controller enforcing it, an unsigned image still runs.

What does a bare cosign verify actually prove?

Very little. Without a pinned certificate identity and OIDC issuer, it accepts a valid signature from any identity at all.

What is the risk of keyless signing?

Your OIDC provider becomes the root of trust. Compromise of that account yields genuine, verifiable signatures, so account security is the control that matters.

Should we expect breaking changes?

Yes. Version 4 is announced to remove roughly half the flags, and a post-quantum migration is named as a further breaking change after that.

Share

Keep looking

Where to go from Cosign

Best Cybersecurity software for

Compare Cosign with

Other Cybersecurity software

  • Free public signing and transparency infrastructure for open source artifacts

    Open source12 researched notes
  • Generates a software bill of materials from images, filesystems and archives

    Open source12 researched notes
  • Secure-by-default open source software with hardened container images and libraries

    Free, then $19,000/yr11 researched notes
  • Manage secrets and protect sensitive data

    Free plan11 researched notes
  • Security infrastructure for developers and AI agents

    Free, then $20/mo10 researched notes
  • Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.

    Free plan14 researched notes
  • The world's foremost network protocol analyzer

    Free plan8 researched notes
  • Open source password management for everyone

    Free, then $1.65/mo12 researched notes
  • Open-source static analysis tool for finding security bugs and enforcing code standards.

    Free, then $30/mo10 researched notes
  • Open-source vulnerability and misconfiguration scanner

    Open source7 researched notes
  • Open-source identity provider with flexible authentication flows

    Free plan9 researched notes
  • Manage and protect cloud-connected endpoints across device platforms, apps and operating systems

    From $8/mo9 researched notes
  • Data access governance and change auditing across Active Directory, file shares and Microsoft 365

    Pricing on request11 researched notes
  • Consumer and business VPN from Nord Security, registered in Panama, with repeated third-party no-logs audits.

    From $3.99/mo14 researched notes
  • Identity governance and administration focused on access certification and compliance evidence

    Pricing on request11 researched notes
  • Open-source identity, authentication, and permissions infrastructure

    Free, then $64/mo8 researched notes
  • High-speed Swiss VPN that safeguards your privacy

    Free plan7 researched notes
  • Vulnerability scanner for container images and filesystems

    Open source8 researched notes

Softwr does not host reviews and shows no star rating for Cosign, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Cosign

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare Cosign with alternatives