Sigstore - Software Artifact Signing and Verification
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cosign
Per Sigstore Cosign: sign + verify container images + OCI artifacts. Integrate with admission control + supply chain security.
- Sigstore evidence for SIGSTORE-3
- adoption + private deployment partial
Keyless Signing
Per Sigstore: keyless signing. Requirements include (a) Keyless Signing With Short-Lived Certificates via Fulcio + (b) OIDC identity-based signing + (c) Certificate Transparency Monitoring + (d) Reusable Workflow and Pipeline Hardening + (e) maintain Sigstore client integration.
- Sigstore evidence for SIGSTORE-1
- adoption + private deployment partial
Private Deployment
Per Sigstore: private deployment + migration. Requirements include (a) Private Sigstore Deployment for Regulated Environments + (b) Long-Lived Key Migration and Sunset + (c) operate enterprise-internal Sigstore.
- Sigstore evidence for SIGSTORE-4
- adoption + private deployment partial
Sigstore: Cosign Signing and Storage
Support identity-based keyless signing using Fulcio certificates and Rekor transparency log by default
- Cosign deployment documentation
- OIDC identity provider integration
- ephemeral key procedures
- signing pipeline records
- no OIDC integration
- long-lived keys persisting
- no signing in CI/CD
Support signing with hardware tokens, KMS systems, or cosign-generated encrypted key pairs
- key generation procedures
- key storage documentation
- key rotation records
- signing pipeline integration
- weak key storage
- no rotation
- no HSM use
Store signatures and attestations in OCI-compliant registries alongside container images
- OCI registry configuration
- signature attachment procedures
- registry access controls
- retention policy
- signatures not stored alongside artifacts
- weak access controls
- no retention policy
Verify signed artifacts using timestamps and short-lived certificate validity windows
- verification policies
- admission controller configurations
- verification logs
- policy bundle records
- no admission controller
- weak verification policies
- missing logs
Sigstore: Fulcio Certificate Authority
Issue short-lived certificates binding ephemeral keys to OpenID Connect identities
- Fulcio integration records
- ephemeral certificate logs
- lifetime policy documentation
- monitoring records
- overly long certificate lifetimes
- no Fulcio integration
- weak monitoring
Bind signer identity from OIDC provider to certificate for attributable signing without long-lived keys
- OIDC provider integration
- identity claim documentation
- binding verification records
- policy mapping
- weak identity mapping
- no policy enforcement on identity claims
- missing audit
Log all issued certificates to certificate transparency logs for auditability
- CT log monitoring records
- SCT verification procedures
- log inclusion proofs
- audit records
- no CT monitoring
- weak SCT verification
- missing inclusion proofs
Sigstore: Rekor Transparency Log
Log all signing events in immutable transparency log providing auditable record of signature creation
- Rekor log entries
- inclusion proof records
- log monitoring procedures
- audit records
- no Rekor logging
- no inclusion proof verification
- weak monitoring
Store entries in append-only Merkle tree providing tamper-evident and verifiable record of signing events
- Merkle tree verification records
- consistency proof logs
- monitoring procedures
- audit reports
- no consistency proof checks
- weak monitoring
- no auditor role
Provide RESTful API for submission, validation, and querying of transparency log entries
- API integration documentation
- validation procedures
- API rate limiting records
- test results
- no API integration testing
- weak rate limiting
- missing validation
Sigstore: Verification and Policy Enforcement
Verify signed timestamp in bundle ensuring it falls within certificate issuance time window
- timestamp authority integration
- timestamp verification records
- TSA configuration documentation
- audit logs
- no TSA integration
- weak verification
- no audit
Support in-toto attestation format for software supply chain metadata and provenance verification
- in-toto attestations
- SLSA framework alignment records
- provenance documents
- verification policies
- no provenance generation
- weak SLSA alignment
- missing verification
Enforce admission policies in container orchestrators to require valid Sigstore signatures before deployment
- policy bundles
- policy controller configurations
- enforcement logs
- policy versioning records
- no policy bundles
- weak controller deployment
- missing versioning
Transparency Log
Per Sigstore: Rekor transparency log. Requirements include (a) record signing events to Rekor + (b) verify signatures + Rekor entries + (c) implement verification policy + (d) integrate with consumers.
- Sigstore evidence for SIGSTORE-2
- adoption + private deployment partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Sigstore - Software Artifact Signing and Verification framework page.