Sigstorevs
Cosign


Cosign: The client, if what you need is the signing command rather than the infrastructure

Free public signing and transparency infrastructure for open source artifacts
As of 31 August 2026, Sigstore is free to use. An OpenSSF project providing a free certificate authority and public transparency log, run as a public good on a 99. Softwr lists it under Cybersecurity. Sigstore is made by Open Source Security Foundation, Linux Foundation, available on Web, Linux, macOS, Windows.
Overview
Sigstore is the umbrella for the components that make keyless signing work: Fulcio, a certificate authority that issues short-lived certificates against an OIDC identity, Rekor, an append-only transparency log recording every signature, Cosign as the client, plus a timestamp authority, a policy controller and clients across most major languages. It is governed under the Open Source Security Foundation at the Linux Foundation, with contributions from Google, Red Hat, Chainguard, GitHub and Purdue University, and everything is Apache 2.0. The public instance is free to everyone, which is the point and also the exposure. It runs to a 99.5 percent availability objective, which is an objective and not an agreement: there is no contract, no remedy and no escalation path beyond a Slack channel and GitHub issues. If a build pipeline signs on every commit and Fulcio is unavailable, builds fail; if an admission controller verifies online, deploys fail. Certificates are valid for ten minutes, so verifying anything older depends on the log entry proving the signature happened inside that window, which couples artifact trust to the permanent availability of a free service. One detail is easy to get wrong and worth stating precisely. Rekor version 2 reached general availability in October 2025, but the public instance still runs version 1 as its default log and the project has said it will for the foreseeable future, bundling that disruption with a later post-quantum migration rather than breaking clients twice. Anyone who read the availability announcement and assumed the flagship instance had migrated is mistaken.
The honest half
Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Sigstore.
Cross-shopped
Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.


Cosign: The client, if what you need is the signing command rather than the infrastructure


Syft: A different question entirely: what is inside the artifact rather than who signed it
Pricing
Taken from the vendor's own pricing page. Prices move, so check before you buy.
Public good instance
Free
Self-hosted
Free
Capabilities
Fulcio
A free certificate authority issuing ten-minute certificates against an OIDC identity
Rekor
An append-only public transparency log of signatures, sharded and running to billions of entries
Keyless signing
No long-lived private key to store, rotate or lose
Multi-language clients
Official clients in Go, Python, JavaScript, Java, Rust and others
Timestamp authority
Independent timestamping for signatures
Neutral governance
OpenSSF and Linux Foundation oversight rather than a single vendor
Answered, with sources
Each answer names the page it came from, so you can check it rather than take our word for it.
Yes, with no contract and no paid tier. That is also the weakness: a 99.5 percent objective with no agreement, no remedy and support through Slack.
No. Version 2 reached general availability in October 2025 and self-hosters can use it, but the public instance still defaults to version 1 and the project has said it will for the foreseeable future.
No, and this is a category error worth avoiding. It tells you who published something. It has no knowledge of what the artifact contains or whether it is vulnerable.
Not published. Only the 100KB cap per attestation upload is documented, so do not design a high-volume pipeline around assumed throughput.
If a public record of every signature is unacceptable, or if a free service with no agreement cannot sit in your build path, then yes. Otherwise the public instance is what most projects use.
Keep looking
Signs and verifies container images and artifacts, with or without managing keys
Generates a software bill of materials from images, filesystems and archives
Open-source identity and authentication infrastructure for apps and APIs
Secure-by-default open source software with hardened container images and libraries
Open-source identity, authentication, and permissions infrastructure
Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.
Open-source static analysis tool for finding security bugs and enforcing code standards.
Open-source identity provider with flexible authentication flows
Open-source authentication and two-factor portal for reverse proxies
Risk, incident and investigations platform for corporate security and operational risk teams, owned by Kroll
Cloud identity governance with privileged access in the same platform
Data and AI security posture management with privacy operations on a single data catalogue
AI control plane for governing enterprise agents, MCP servers, and skills
Cloud-native runtime security platform with real-time detection and response
AI-powered exposure management platform for unified security visibility
Softwr does not host reviews and shows no star rating for Sigstore, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.
What people switch to, and what they give up
Every tier, and where the cost actually lands
Put it head to head with anything we hold
Its rating, and an embed for your own site
Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use
quoteManaged video loss prevention with human auditors for restaurants, convenience stores and retail
quoteWorkforce and customer authentication from a certificate authority
Per user per monthPrivileged access management, endpoint privilege management and secure remote access
quoteCloud video surveillance billed per camera per month, where retention length drives the bill more than anything else
Per camera per monthAI video search that runs on cameras you already own, starting near five dollars per camera per month
Per camera per monthPhishing-resistant passwordless authentication with device trust enforced at every login
quote