Skip to content

project

cosign

Open-source Sigstore tool for signing, verifying, and storing cryptographic signatures on container images and software artifacts.

Current stories

build1 publisher

Your agent needs the API call, not the API key

A developer's argument that .env access is an architectural bug in agent workflows, and a small Go CLI that brokers credentials at the process and transport boundary instead.

Publishers:dev.to

Reality

Evidence30
Adoption
Insufficient
Hype gap+28
Incentives70
Confidence38