Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up

Common go library shared across sigstore services and clients

License

NotificationsYou must be signed in to change notification settings

sigstore/sigstore

Fuzzing StatusCII Best Practices

sigstore/sigstore contains commonSigstore code: that is, code shared by infrastructure (e.g.,Fulcio andRekor) and Go language clients (e.g.,Cosign andGitsign).

This library currently provides:

  • A signing interface (support for ecdsa, ed25519, rsa, DSSE (in-toto))
  • OpenID Connect fulcio client code

The following KMS systems are available:

  • AWS Key Management Service
  • Azure Key Vault
  • HashiCorp Vault
  • Google Cloud Platform Key Management Service

For example code, look at the relevant test code for each main code file.

Fuzzing

The fuzzing tests are withinhttps://github.com/sigstore/sigstore/tree/main/test/fuzz

Security

Should you discover any security issues, please refer to sigstoressecurityprocess

For container signing, you wantcosign


[8]ページ先頭

©2009-2025 Movatter.jp