Skip to main content

No project description provided

Project description

About

This project implements a signing and verification process using Sigstore’s tools for Software Supply Chain Security. We use cosign to sign an artifact and store it in a transparency log, and Python code to verify the artifact's inclusion, signature, and consistency.

Usage Instructions

  • Artifact Creation: Add your content to artifact.md.
  • Signing and Uploading: Use cosign to sign artifact.md and upload it to Rekor's transparency log.
  • Verification: Run the Python script to verify inclusion, signature, and consistency with Rekor log checkpoints.

Installation

  1. Install cosign: Installation Guide
  2. Clone this repository.
  3. Install dependencies using pip install -r requirements.txt.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

py_rekor_monitor_ss17542_sscs-0.1.0.tar.gz (17.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

py_rekor_monitor_ss17542_sscs-0.1.0-py3-none-any.whl (19.5 kB view details)

Uploaded Python 3

File details

Details for the file py_rekor_monitor_ss17542_sscs-0.1.0.tar.gz.

File metadata

File hashes

Hashes for py_rekor_monitor_ss17542_sscs-0.1.0.tar.gz
Algorithm Hash digest
SHA256 f84006c6703c7ddea9724fbc3f6a2bb7b26f4c40e57625f0dbbc2a791e63768d
MD5 c5942e6c1ca43236786873a1b2c1f08d
BLAKE2b-256 bfa7e8bbb33cbc28821a7be5b29aee5a2dc7a97a44fb237b4502b890c6055b7d

See more details on using hashes here.

File details

Details for the file py_rekor_monitor_ss17542_sscs-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for py_rekor_monitor_ss17542_sscs-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 28ef3e842bf07ff5bd5c64bfbf5a670bb0aae754db14ae7783bea617811506a8
MD5 c0ee67340e80714f954298bec553683d
BLAKE2b-256 0275ddc726ad7011147e63badbc8cd1f9edb84fcca7ccc561306daf417e1c6f6

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page