macOS
brew install sigsum-golocal Homebrew formula metadata
brew / rank 9186
Key transparency toolkit. Version 0.14.1 via Homebrew; verified 2026-09-13. Also installable with debian: sudo apt install golang-sigsum-sigsum-go-dev.
install
brew install sigsum-golocal Homebrew formula metadata
sudo apt install sigsum-goDebian stable package indexes · sigsum-go · source: deb.debian.org
overview
Key transparency toolkit
history
sigsum-go is the Go implementation and command-line toolkit for Sigsum key-usage transparency.
sigsum-go is the principal Go implementation of Sigsum, a system for key-usage transparency based on signed checksums, append-only logs, witnesses, and monitors. The module contains command-line clients and reusable Go packages implementing Sigsum formats and protocols.
Sigsum remains a focused transparency ecosystem rather than a general-purpose signing platform. Its official documentation lists Go, C, and Rust implementations and provides tooling for users, monitors, log operators, and witnesses.
Users generate Ed25519 keys, sign and submit checksums to a configured log, collect witness-backed proofs, verify proofs offline, and monitor logs for use of selected signing keys. Trust policies identify accepted logs, witnesses, and quorum rules.
sigsum-go interests release engineers because it supplies compact, interoperable tools for proving that signed checksums were publicly logged. Offline proof verification and witness-backed append-only guarantees suit reproducible release and package-verification workflows.
security posture
narrow executable package without higher-risk signals.
green risk · low confidence · appliance
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
sigsum-key | cli | global executable | |
sigsum-monitor | cli | global executable | |
sigsum-submit | cli | global executable | |
sigsum-token | cli | global executable | |
sigsum-verify | cli | global executable | |
sigsum-witness | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:sigsum-go |
|---|---|
| Version | 0.14.1 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/sigsum-go |
| Homepage | https://sigsum.org |
| Upstream docs | https://sigsum.org |
| License | BSD-2-Clause |
| Source archive | https://git.glasklar.is/sigsum/core/sigsum-go/-/archive/v0.14.1/sigsum-go-v0.14.1.tar.bz2 |
| Last updated | 2026-09-13T02:26:54Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | sigsum-go |
| Version Scheme | 0 |
| Revision | 0 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
golang-sigsum-sigsum-go-dev 0.11.2-1
tools for public and transparent logging of signed checksums (library)
https://git.glasklar.is/sigsum/core/sigsum-go
sudo apt install golang-sigsum-sigsum-go-devsigsum-go 0.11.2-1+b3
tools for public and transparent logging of signed checksums
https://git.glasklar.is/sigsum/core/sigsum-go
sudo apt install sigsum-gogolang-sigsum-sigsum-go-dev 0.7.2-2
tools for public and transparent logging of signed checksums (library)
sudo apt install golang-sigsum-sigsum-go-devsigsum-go 0.7.2-2
tools for public and transparent logging of signed checksums
sudo apt install sigsum-gosource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.