Skip to main content
https://github.com/ralphje/signify/actions/workflows/test.yml/badge.svg https://codecov.io/gh/ralphje/signify/branch/master/graph/badge.svg https://readthedocs.org/projects/signify/badge/?version=latest

Signify, a portmanteau of signature and verify, is a Python module that provides validation and inspection of digital code signatures. These types of signatures are used to verify the authenticity and integrity of executable code, providing assurance about who published a piece of software and whether is has been altered since it was signed.

This library is mostly intended for malware analysts and security professionals to allow validation of these signatures outside their normal ecosystem and enable close inspection of the available data.

Currently, this library is only able to verify Windows Authenticode signatures, the specific Microsoft technology that is used in Windows to verify software integrity. Typically, Authenticode signatures are embedded into the file itself, without altering the functionality of the software. However, these signatures can also be provided by external Authenticode catalogs (.cat files), allowing virtually any file to be signed using this technology.

The following file types are supported, with support for other file types being expected:

  • PE executables (.exe, .dll and various other Windows executables)

  • MSI files (.msi)

  • Catalog files (.stl and .cat)

  • Any flat file that is signed through a catalog file

This module is compatible with Python 3.9+.

Installation

Installation is very simple:

pip install signify

Support for some file types (including MSI) requires:

pip install signify[full]

Documentation

Documentation is available at http://signify.readthedocs.io/en/latest/ or in the docs/ directory.

Thanks

Huge thanks to Germano Caronni for writing the original code in the verify_sigs project, on which this project was based.

A multitude of significant improvements and modifications was made on top of their original contribution, including improving PE signature support, adding support for various other files, and moving the original scripts into a modern Python module.

Metadata

Release files for signify 0.9.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for signify 0.9.2
File Size Uploaded
signify-0.9.2.tar.gz 90.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for signify 0.9.2
File Interpreter ABI Platform
signify-0.9.2-py3-none-any.whl Python 3 none any Details

Total release size: 178.8 kB

Release files / signify-0.9.2.tar.gz

Download URL signify-0.9.2.tar.gz
Size 90.4 kB
Tags Source
SHA-256 checksum
How to use checksums
e504d26184b4df3802104d1bdd9c5074c030246c9febf184acd694822d610287
BLAKE2b-256 checksum
How to use checksums
a7d4420073deaaf9caa50e0daa5a04d5247ae5a174f515b35f932ba8e6f7ce3a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release files / signify-0.9.2-py3-none-any.whl

Download URL signify-0.9.2-py3-none-any.whl
Size 88.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9bbe43a2198dc8f21ae6c3c41227b695b4c3b7c242e2d2b19c3af7af4f29d2c5
BLAKE2b-256 checksum
How to use checksums
b0218d4579d439b3c03ae5cf5fb5e0d9151d34b4d9e24a50876ea211c2f48d3b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.9.2 This release

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.1

1 release file

0.7.0

1 release file

0.6.1

1 release file

0.6.0

1 release file

0.5.2

1 release file

0.5.1

1 release file

0.5.0

1 release file

0.4.0

1 release file

0.3.0

1 release file

0.2.0

1 release file

0.1.5

1 release file

0.1.4

1 release file

0.1.3

1 release file

0.1.2

1 release file

0.1.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page