← Home

@sigstore/sign

Sigstore signing library

1
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bdehamer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@sigstore/core AI (dependencies): @sigstore/core is a sibling package in the same sigstore-js monorepo; it is a legitimate first-party dependency of @sigstore/sign and not a third-party risk. ai

Versions (showing 1 of 1)

Version Deps Published
4.1.1 6 / 4