← Registry

cosign

Community

Expert guidance for Cosign, the Sigstore tool for signing, verifying, and attaching metadata to container images and other OCI artifacts. Helps developers implement supply chain security by signing images in CI/CD, verifying signatures before deployment, and attaching SBOMs and vulnerability scan results as attestations.

Install

skillpm install cosign

Format score

100/100

Spec

v1.0

Installs

0

Published

April 1, 2026