-
Notifications
You must be signed in to change notification settings - Fork 100
Open
Description
gitsign is a unique case, it's more like Cosign in that it's a tool built on top of an SDK to sign a specific format (commits, rather than containers/blobs like Cosign).
What do you think about an additional section for Sigstore tooling that is not Cosign? Something like:
- Cosign
- Sign
- Verify
- Etc
- Client libraries
- sigstore-python
- sigstore-java
- etc
- Sigstore tools
- gitsign
- model signing (https://github.com/sigstore/model-transparency)
- In the future, more tools
If we were to ever refactor Cosign to be smaller in scope to only support container signing, it would then just move under Sigstore tooling, though I don't expect that to happen. But it would give us a category to expand over time as more use cases for Sigstore signing arise.
Originally posted by @haydentherapper in #323 (comment)
mihaimaruseac
Metadata
Metadata
Assignees
Labels
No labels