macOS
brew install sigsum-golocal Homebrew formula metadata
brew / Rang 9186
Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für sigsum-go in AI-Agent-Workflows.
Installation
brew install sigsum-golocal Homebrew formula metadata
sudo apt install sigsum-goDebian stable package indexes · sigsum-go · Quelle: deb.debian.org
Überblick
Key transparency toolkit
Verlauf
sigsum-go is the Go implementation and command-line toolkit for Sigsum key-usage transparency.
sigsum-go is the principal Go implementation of Sigsum, a system for key-usage transparency based on signed checksums, append-only logs, witnesses, and monitors. The module contains command-line clients and reusable Go packages implementing Sigsum formats and protocols.
Sigsum remains a focused transparency ecosystem rather than a general-purpose signing platform. Its official documentation lists Go, C, and Rust implementations and provides tooling for users, monitors, log operators, and witnesses.
Users generate Ed25519 keys, sign and submit checksums to a configured log, collect witness-backed proofs, verify proofs offline, and monitor logs for use of selected signing keys. Trust policies identify accepted logs, witnesses, and quorum rules.
sigsum-go interests release engineers because it supplies compact, interoperable tools for proving that signed checksums were publicly logged. Offline proof verification and witness-backed append-only guarantees suit reproducible release and package-verification workflows.
Sicherheitslage
narrow executable package without higher-risk signals.
grün Risiko · niedrig Konfidenz · appliance
Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.
Executables
| Befehl | Art | Sichtbarkeit | Hinweis |
|---|---|---|---|
sigsum-key | cli | globales Executable | |
sigsum-monitor | cli | globales Executable | |
sigsum-submit | cli | globales Executable | |
sigsum-token | cli | globales Executable | |
sigsum-verify | cli | globales Executable | |
sigsum-witness | cli | globales Executable |
Aktualität
Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.
Installationsmetadaten
| Paketschlüssel | brew:sigsum-go |
|---|---|
| Version | 0.14.1 |
| Paketmanager | Homebrew |
| Paketmanager-Seite | https://formulae.brew.sh/formula/sigsum-go |
| Homepage | https://sigsum.org |
| Upstream-Dokumentation | https://sigsum.org |
| Lizenz | BSD-2-Clause |
| Quellarchiv | https://git.glasklar.is/sigsum/core/sigsum-go/-/archive/v0.14.1/sigsum-go-v0.14.1.tar.bz2 |
| Zuletzt aktualisiert | 2026-09-13T02:26:54Z |
| Pulse | updated |
| Build-Abhängigkeiten | go |
| Bottle | verfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | nicht definiert |
| Dienst | keiner deklariert |
Registry-Fakten
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | sigsum-go |
| Version Scheme | 0 |
| Revision | 0 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
Source-Datenbank-Treffer
Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.
golang-sigsum-sigsum-go-dev 0.11.2-1
tools for public and transparent logging of signed checksums (library)
https://git.glasklar.is/sigsum/core/sigsum-go
sudo apt install golang-sigsum-sigsum-go-devsigsum-go 0.11.2-1+b3
tools for public and transparent logging of signed checksums
https://git.glasklar.is/sigsum/core/sigsum-go
sudo apt install sigsum-gogolang-sigsum-sigsum-go-dev 0.7.2-2
tools for public and transparent logging of signed checksums (library)
sudo apt install golang-sigsum-sigsum-go-devsigsum-go 0.7.2-2
tools for public and transparent logging of signed checksums
sudo apt install sigsum-goQuellspur
Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.
View the package source record on GitHub.