pkg.soopen package index

brew / Rang 4675

sigstore mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für sigstore in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install sigstore

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Codesigning tool for Python packages

Befehle und Aliase

  • sigstore

Verlauf

Projektgeschichte und Nutzung

sigstore-python is a Python command-line tool and library for generating and verifying Sigstore signatures, including signatures for Python package distributions.

Projektgeschichte

sigstore-python was created as the Python client for the broader Sigstore software-signing ecosystem. It combines a command-line program with an importable API for keyless signing and verification using OpenID Connect identities, Fulcio certificates, and Rekor transparency records.

Adoptionsgeschichte

The project provides an official GitHub Action and supports ambient identities from CI and cloud environments, making it suitable for automated release pipelines as well as local signing. It is particularly relevant to Python packaging because the documentation explicitly covers signing Python distributions.

Wie es verwendet wird

Users run sigstore sign to create a signature bundle for an artifact and sigstore verify commands to validate bundles against expected identities. Signing can use ambient CI credentials, an interactive OAuth flow, or an explicitly supplied identity token.

Warum Paket-Nerds sich dafür interessieren

sigstore-python gives Python users and package maintainers a native implementation of Sigstore's keyless signing model. It replaces long-lived signing keys with short-lived identity-bound certificates and records signing events in a public transparency service.

Zeitleiste

  • 2022: Early public sigstore-python releases established Python-native keyless signing and verification.
  • 2023: The project expanded its documented CI integration and official GitHub Action workflow.
  • 2025: The 4.x series introduced substantial client and trust-configuration API changes.

Related projects

  • Related official Sigstore projects include Fulcio, Rekor, Cosign, sigstore-go, and the Sigstore client specifications.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für sigstore wurde kein passendes lokales Secret-Handling-Manifest gefunden. Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Installiert mit 5 Laufzeitabhängigkeiten.
  • Build-Metadaten listen 2 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
sigstorecliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-09-19
Manager-Version4.5.0
Manager aktualisiert2026-09-13
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://github.com/sigstore/sigstore-python

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:sigstore
Version4.5.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/sigstore
Homepagehttps://github.com/sigstore/sigstore-python
Repositoryhttps://github.com/sigstore/sigstore-python
LizenzApache-2.0
Quellarchivhttps://files.pythonhosted.org/packages/18/e0/279419065e2d7102413605b3456122adbbccbc42e010b499c7b882fc01f8/sigstore-4.5.0.tar.gz
Zuletzt aktualisiert2026-09-13T02:34:55Z
Pulseupdated
Abhängigkeitencertifi, cryptography, openssl@3, pydantic, python@3.14
Build-Abhängigkeitenpkgconf, rust
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesigstore
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation