macOS
brew install cosignlocal Homebrew formula metadata
sudo port install cosignMacPorts ports tree · security/cosign/Portfile · ソース: api.github.com
brew
cosign のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。
インストール
brew install cosignlocal Homebrew formula metadata
sudo port install cosignMacPorts ports tree · security/cosign/Portfile · ソース: api.github.com
sudo apk add cosignAlpine Linux edge package indexes · cosign · ソース: dl-cdn.alpinelinux.org
sudo apt install cosignDebian stable package indexes · cosign · ソース: deb.debian.org
nix profile install nixpkgs#cosignnixpkgs package indexes · pkgs/by-name/co/cosign/package.nix · ソース: api.github.com
sudo pacman -S cosignArch Linux sync databases · cosign · ソース: geo.mirror.pkgbuild.com
sudo zypper install cosignopenSUSE Tumbleweed package metadata · cosign · ソース: download.opensuse.org
scoop install main/cosignScoop official bucket manifest trees · bucket/cosign.json · ソース: api.github.com
winget install --id Sigstore.Cosign -eWindows Package Manager source index · Sigstore.Cosign · ソース: cdn.winget.microsoft.com
概要
Container Signing
履歴
cosign is Sigstore's command-line signing and verification tool for OCI containers, blobs, and other artifacts. It helped make software-supply-chain signing a normal packaging and CI concern by combining artifact signatures, OIDC identities, Fulcio certificates, Rekor transparency logging, and registry-native storage.
The sigstore/cosign repository was created in February 2021 and published early releases the following month. The README describes cosign as part of the Sigstore project and frames its goal as making signatures invisible infrastructure, which matches its role as the user-facing CLI for Sigstore signing workflows.
cosign spread through container and release pipelines because it supports keyless signing by default while still allowing hardware, KMS, generated key pairs, and bring-your-own PKI. Official installation docs and package metadata show it distributed through common developer package channels including Homebrew, Linux distributions, Nix, Scoop, and winget.
Common package-nerd usage is to sign images by digest, verify images against expected OIDC identity and issuer values, sign or verify blobs, and publish signatures or attestations alongside artifacts in OCI registries. The README also documents offline verification and generic artifact upload flows.
cosign matters to package ecosystems because it turns artifact authenticity into a reproducible command-line step. It is often used by maintainers and downstream packagers to verify upstream release assets, container images, SBOMs, and attestations without each project inventing a bespoke signing scheme.
セキュリティ状態
infrastructure mutation or orchestration signal.
リスク orange · 信頼度 中 · infrastructure
エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。
実行可能ファイル
| コマンド | 種類 | 公開範囲 | メモ |
|---|---|---|---|
cosign | cli | グローバル実行可能ファイル |
鮮度
これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。
https://github.com/sigstore/cosign
インストールメタデータ
| パッケージキー | brew:cosign |
|---|---|
| バージョン | 3.1.2 |
| パッケージマネージャ | Homebrew |
| パッケージマネージャページ | https://formulae.brew.sh/formula/cosign |
| ホームページ | https://github.com/sigstore/cosign |
| リポジトリ | https://github.com/sigstore/cosign |
| 上流ドキュメント | https://docs.sigstore.dev/cosign |
| ライセンス | Apache-2.0 |
| ソースアーカイブ | https://github.com/sigstore/cosign.git |
| 最終更新 | 2026-07-17T17:59:14Z |
| Pulse | updated |
| ビルド依存関係 | go |
| Bottle | 利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定義 |
| サービス | 宣言なし |
レジストリ情報
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | cosign |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
ソースデータベース一致
一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。
cosign 2.5.0-2+b4
Code signing/transparency for containers and binaries (program)
https://github.com/sigstore/cosign
sudo apt install cosigngolang-github-sigstore-cosign-dev 2.5.0-2
Code signing/transparency for containers and binaries (library)
https://github.com/sigstore/cosign
sudo apt install golang-github-sigstore-cosign-devcosign
nix profile install nixpkgs#cosigncosign 3.0.6-r1
container signing tool with support for ephemeral keys and Sigstore signing
https://github.com/sigstore/cosign
sudo apk add cosigncosign-bash-completion 3.0.6-r1
Bash completions for cosign
https://github.com/sigstore/cosign
sudo apk add cosign-bash-completioncosign-fish-completion 3.0.6-r1
Fish completions for cosign
https://github.com/sigstore/cosign
sudo apk add cosign-fish-completioncosign-zsh-completion 3.0.6-r1
Zsh completions for cosign
https://github.com/sigstore/cosign
sudo apk add cosign-zsh-completioncosign 3.0.6-1
Container Signing with support for ephemeral keys and Sigstore signing
https://github.com/sigstore/cosign
sudo pacman -S cosigncosign 3.0.6-1.1
Container Signing, Verification and Storage in an OCI registry
https://github.com/sigstore/cosign
sudo zypper install cosigncosign-bash-completion 3.0.6-1.1
Bash Completion for cosign
https://github.com/sigstore/cosign
sudo zypper install cosign-bash-completioncosign-fish-completion 3.0.6-1.1
Fish Completion for cosign
https://github.com/sigstore/cosign
sudo zypper install cosign-fish-completioncosign-zsh-completion 3.0.6-1.1
Zsh Completion for cosign
https://github.com/sigstore/cosign
sudo zypper install cosign-zsh-completioncosign
sudo port install cosignmain/cosign
scoop install main/cosignSigstore.Cosign
winget install --id Sigstore.Cosign -eソース経路
このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。
View the package source record on GitHub.