Softwr
Sigstore logo

Sigstore

Free public signing and transparency infrastructure for open source artifacts

As of 31 August 2026, Sigstore is free to use. An OpenSSF project providing a free certificate authority and public transparency log, run as a public good on a 99. Softwr lists it under Cybersecurity. Sigstore is made by Open Source Security Foundation, Linux Foundation, available on Web, Linux, macOS, Windows.

Overview

What Sigstore does

Sigstore is the umbrella for the components that make keyless signing work: Fulcio, a certificate authority that issues short-lived certificates against an OIDC identity, Rekor, an append-only transparency log recording every signature, Cosign as the client, plus a timestamp authority, a policy controller and clients across most major languages. It is governed under the Open Source Security Foundation at the Linux Foundation, with contributions from Google, Red Hat, Chainguard, GitHub and Purdue University, and everything is Apache 2.0. The public instance is free to everyone, which is the point and also the exposure. It runs to a 99.5 percent availability objective, which is an objective and not an agreement: there is no contract, no remedy and no escalation path beyond a Slack channel and GitHub issues. If a build pipeline signs on every commit and Fulcio is unavailable, builds fail; if an admission controller verifies online, deploys fail. Certificates are valid for ten minutes, so verifying anything older depends on the log entry proving the signature happened inside that window, which couples artifact trust to the permanent availability of a free service. One detail is easy to get wrong and worth stating precisely. Rekor version 2 reached general availability in October 2025, but the public instance still runs version 1 as its default log and the project has said it will for the foreseeable future, bundling that disruption with a later post-quantum migration rather than breaking clients twice. Anyone who read the availability announcement and assumed the flagship instance had migrated is mistaken.

What people use it for

  • Open source projects signing releases without running a certificate authority
  • Organisations meeting a signed-artifact requirement without buying a signing product
  • Publishing provenance that a consumer can verify independently of you
  • Self-hosting the same components where a public log is unacceptable

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Sigstore.

  • The security model depends on somebody watching the log. The documentation states that compromise of an identity provider or of Fulcio itself is detectable only if third parties monitor the transparency log, the monitoring tool is a community-tier rather than core project, and almost no consumer runs one.
  • It is a 99.5 percent objective with no service level agreement, which permits several hours of downtime a month and offers no remedy. A pipeline that signs on every build has taken a hard dependency on a free service with no contract behind it.
  • Log scale is a live engineering problem rather than a theoretical one. The active shard holds billions of entries, the log has already been sharded twice, and sharding version 1 requires stopping traffic, which is why a replacement was built.
  • Ten-minute certificates make trust depend on log availability. Verifying an older signature relies on the log entry proving it was made inside that window, so a lost or unreachable entry can render a valid artifact unverifiable.
  • Migration debt is substantial and ongoing. Version 2 of the log is generally available but not the public default, the signing client has an announced breaking release ahead, some official clients lag the new log format, and a post-quantum migration is named as the next break after that.

Cross-shopped

What people choose instead of Sigstore

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

  • Sigstore logo
    Sigstore
    vs
    Cosign logo
    Cosign

    Cosign: The client, if what you need is the signing command rather than the infrastructure

  • Sigstore logo
    Sigstore
    vs
    Syft logo
    Syft

    Syft: A different question entirely: what is inside the artifact rather than who signed it

Pricing

What Sigstore costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Public good instance

Free

  • Free to everyone with no contract
  • 99.5 percent availability objective, not an agreement
  • 100KB cap per attestation upload
  • Support is a Slack channel and GitHub issues

Self-hosted

Free

  • Apache-2.0
  • Run your own Fulcio and Rekor
  • Rekor v2 available for self-hosters
  • Infrastructure and operation are yours

Capabilities

Features

  • Fulcio

    A free certificate authority issuing ten-minute certificates against an OIDC identity

  • Rekor

    An append-only public transparency log of signatures, sharded and running to billions of entries

  • Keyless signing

    No long-lived private key to store, rotate or lose

  • Multi-language clients

    Official clients in Go, Python, JavaScript, Java, Rust and others

  • Timestamp authority

    Independent timestamping for signatures

  • Neutral governance

    OpenSSF and Linux Foundation oversight rather than a single vendor

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Is the public instance really free?

Yes, with no contract and no paid tier. That is also the weakness: a 99.5 percent objective with no agreement, no remedy and support through Slack.

Has the public log moved to Rekor v2?

No. Version 2 reached general availability in October 2025 and self-hosters can use it, but the public instance still defaults to version 1 and the project has said it will for the foreseeable future.

Does Sigstore make my dependencies safe?

No, and this is a category error worth avoiding. It tells you who published something. It has no knowledge of what the artifact contains or whether it is vulnerable.

What are the rate limits?

Not published. Only the 100KB cap per attestation upload is documented, so do not design a high-volume pipeline around assumed throughput.

Should we self-host it?

If a public record of every signature is unacceptable, or if a free service with no agreement cannot sit in your build path, then yes. Otherwise the public instance is what most projects use.

Share

Keep looking

Where to go from Sigstore

Best Cybersecurity software for

Compare Sigstore with

Other Cybersecurity software

  • Signs and verifies container images and artifacts, with or without managing keys

    Open source12 researched notes
  • Generates a software bill of materials from images, filesystems and archives

    Open source12 researched notes
  • Open-source identity and authentication infrastructure for apps and APIs

    Free, then $24/mo8 researched notes
  • Security infrastructure for developers and AI agents

    Free, then $20/mo10 researched notes
  • Secure-by-default open source software with hardened container images and libraries

    Free, then $19,000/yr11 researched notes
  • Open-source identity, authentication, and permissions infrastructure

    Free, then $64/mo8 researched notes
  • Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.

    Free plan14 researched notes
  • Open source password management for everyone

    Free, then $1.65/mo12 researched notes
  • Open-source static analysis tool for finding security bugs and enforcing code standards.

    Free, then $30/mo10 researched notes
  • Open-source vulnerability and misconfiguration scanner

    Open source7 researched notes
  • Open-source identity provider with flexible authentication flows

    Free plan9 researched notes
  • Open-source authentication and two-factor portal for reverse proxies

    Open source9 researched notes
  • Risk, incident and investigations platform for corporate security and operational risk teams, owned by Kroll

    Pricing on request13 researched notes
  • Cloud identity governance with privileged access in the same platform

    Pricing on request11 researched notes
  • Data and AI security posture management with privacy operations on a single data catalogue

    Pricing on request13 researched notes
  • AI control plane for governing enterprise agents, MCP servers, and skills

    Pricing on request8 researched notes
  • Cloud-native runtime security platform with real-time detection and response

    Pricing on request12 researched notes
  • AI-powered exposure management platform for unified security visibility

    From $3,500/yr11 researched notes

Softwr does not host reviews and shows no star rating for Sigstore, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Sigstore

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare Sigstore with alternatives