macOS
brew install cosignlocal Homebrew formula metadata
sudo port install cosignMacPorts ports tree · security/cosign/Portfile · 来源: api.github.com
安装
brew install cosignlocal Homebrew formula metadata
sudo port install cosignMacPorts ports tree · security/cosign/Portfile · 来源: api.github.com
sudo apk add cosignAlpine Linux edge package indexes · cosign · 来源: dl-cdn.alpinelinux.org
sudo apt install cosignDebian stable package indexes · cosign · 来源: deb.debian.org
nix profile install nixpkgs#cosignnixpkgs package indexes · pkgs/by-name/co/cosign/package.nix · 来源: api.github.com
sudo pacman -S cosignArch Linux sync databases · cosign · 来源: geo.mirror.pkgbuild.com
sudo zypper install cosignopenSUSE Tumbleweed package metadata · cosign · 来源: download.opensuse.org
scoop install main/cosignScoop official bucket manifest trees · bucket/cosign.json · 来源: api.github.com
winget install --id Sigstore.Cosign -eWindows Package Manager source index · Sigstore.Cosign · 来源: cdn.winget.microsoft.com
概览
Container Signing
历史
cosign is Sigstore's command-line signing and verification tool for OCI containers, blobs, and other artifacts. It helped make software-supply-chain signing a normal packaging and CI concern by combining artifact signatures, OIDC identities, Fulcio certificates, Rekor transparency logging, and registry-native storage.
The sigstore/cosign repository was created in February 2021 and published early releases the following month. The README describes cosign as part of the Sigstore project and frames its goal as making signatures invisible infrastructure, which matches its role as the user-facing CLI for Sigstore signing workflows.
cosign spread through container and release pipelines because it supports keyless signing by default while still allowing hardware, KMS, generated key pairs, and bring-your-own PKI. Official installation docs and package metadata show it distributed through common developer package channels including Homebrew, Linux distributions, Nix, Scoop, and winget.
Common package-nerd usage is to sign images by digest, verify images against expected OIDC identity and issuer values, sign or verify blobs, and publish signatures or attestations alongside artifacts in OCI registries. The README also documents offline verification and generic artifact upload flows.
cosign matters to package ecosystems because it turns artifact authenticity into a reproducible command-line step. It is often used by maintainers and downstream packagers to verify upstream release assets, container images, SBOMs, and attestations without each project inventing a bespoke signing scheme.
安全态势
infrastructure mutation or orchestration signal.
orange 风险 · 中 置信度 · infrastructure
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
cosign | cli | 全局可执行文件 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
https://github.com/sigstore/cosign
安装元数据
| 软件包键 | brew:cosign |
|---|---|
| 版本 | 3.1.2 |
| 软件包管理器 | Homebrew |
| 软件包管理器页面 | https://formulae.brew.sh/formula/cosign |
| 主页 | https://github.com/sigstore/cosign |
| 仓库 | https://github.com/sigstore/cosign |
| 上游文档 | https://docs.sigstore.dev/cosign |
| 许可证 | Apache-2.0 |
| 源码归档 | https://github.com/sigstore/cosign.git |
| 最后更新 | 2026-07-17T17:59:14Z |
| Pulse | updated |
| 构建依赖 | go |
| Bottle | 可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定义 |
| 服务 | 未声明 |
注册表事实
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | cosign |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
源数据库匹配
匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。
cosign 2.5.0-2+b4
Code signing/transparency for containers and binaries (program)
https://github.com/sigstore/cosign
sudo apt install cosigngolang-github-sigstore-cosign-dev 2.5.0-2
Code signing/transparency for containers and binaries (library)
https://github.com/sigstore/cosign
sudo apt install golang-github-sigstore-cosign-devcosign
nix profile install nixpkgs#cosigncosign 3.0.6-r1
container signing tool with support for ephemeral keys and Sigstore signing
https://github.com/sigstore/cosign
sudo apk add cosigncosign-bash-completion 3.0.6-r1
Bash completions for cosign
https://github.com/sigstore/cosign
sudo apk add cosign-bash-completioncosign-fish-completion 3.0.6-r1
Fish completions for cosign
https://github.com/sigstore/cosign
sudo apk add cosign-fish-completioncosign-zsh-completion 3.0.6-r1
Zsh completions for cosign
https://github.com/sigstore/cosign
sudo apk add cosign-zsh-completioncosign 3.0.6-1
Container Signing with support for ephemeral keys and Sigstore signing
https://github.com/sigstore/cosign
sudo pacman -S cosigncosign 3.0.6-1.1
Container Signing, Verification and Storage in an OCI registry
https://github.com/sigstore/cosign
sudo zypper install cosigncosign-bash-completion 3.0.6-1.1
Bash Completion for cosign
https://github.com/sigstore/cosign
sudo zypper install cosign-bash-completioncosign-fish-completion 3.0.6-1.1
Fish Completion for cosign
https://github.com/sigstore/cosign
sudo zypper install cosign-fish-completioncosign-zsh-completion 3.0.6-1.1
Zsh Completion for cosign
https://github.com/sigstore/cosign
sudo zypper install cosign-zsh-completioncosign
sudo port install cosignmain/cosign
scoop install main/cosignSigstore.Cosign
winget install --id Sigstore.Cosign -e来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.