DOCS / STANDARDS / SIGSTORE
Sigstore
A set of tools for signing, verifying, and providing provenance for software artifacts — without managing long-term signing keys.
Components
Fulcio
The certificate authority. Issues short-lived certificates binding an OIDC identity to an ephemeral signing key.
Rekor
The transparency log. Records every signing event in a public, append-only Merkle tree.
Cosign
Client tooling for signing and verification, usable independently of CDK.
Where CDK fits
CDK's entire signing model is built on Sigstore's keyless flow. Every attestation is signed via Fulcio-issued certificates and recorded in Rekor — see the Security Architecture for the full technical breakdown of how identity, signing, and the transparency log fit together.