pkg.soopen package index

brew / 順位 9186

sigsum-go を Homebrew, apt でインストール

sigsum-go のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install sigsum-go

local Homebrew formula metadata

Linux

Debian apt確認済み · 92%
sudo apt install sigsum-go

Debian stable package indexes · sigsum-go · ソース: deb.debian.org

概要

パッケージ概要

Key transparency toolkit

コマンドとエイリアス

  • sigsum-key
  • sigsum-monitor
  • sigsum-submit
  • sigsum-token
  • sigsum-verify
  • sigsum-witness

履歴

プロジェクトの歴史と使われ方

sigsum-go is the Go implementation and command-line toolkit for Sigsum key-usage transparency.

プロジェクトの歴史

sigsum-go is the principal Go implementation of Sigsum, a system for key-usage transparency based on signed checksums, append-only logs, witnesses, and monitors. The module contains command-line clients and reusable Go packages implementing Sigsum formats and protocols.

採用の歴史

Sigsum remains a focused transparency ecosystem rather than a general-purpose signing platform. Its official documentation lists Go, C, and Rust implementations and provides tooling for users, monitors, log operators, and witnesses.

使われ方

Users generate Ed25519 keys, sign and submit checksums to a configured log, collect witness-backed proofs, verify proofs offline, and monitor logs for use of selected signing keys. Trust policies identify accepted logs, witnesses, and quorum rules.

パッケージ好きにとっての重要性

sigsum-go interests release engineers because it supplies compact, interoperable tools for proving that signed checksums were publicly logged. Offline proof verification and witness-backed append-only guarantees suit reproducible release and package-verification workflows.

タイムライン

  • 2021: Sigsum's early design and implementation work became public.
  • 2024: Current development moved to the Glasklar GitLab service.
  • 2025: The official getting-started workflow documented the 0.14 series and built-in trust policies.

Related projects

  • Officially documented related implementations include sigsum-c and sigsum-rs. The broader system also includes Sigsum log servers, witnesses, bastions, monitors, and community-maintained trust policies.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • ビルドメタデータには 1 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
sigsum-keycliグローバル実行可能ファイル
sigsum-monitorcliグローバル実行可能ファイル
sigsum-submitcliグローバル実行可能ファイル
sigsum-tokencliグローバル実行可能ファイル
sigsum-verifycliグローバル実行可能ファイル
sigsum-witnesscliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-09-19
マネージャ版0.14.1
マネージャ更新日2026-09-13
ローカルデータOK
上流not checked
検出された最新未検出

https://sigsum.org

  • 情報Release/tag comparison is only available for GitHub repositories.https://sigsum.org信頼度 none

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:sigsum-go
バージョン0.14.1
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/sigsum-go
ホームページhttps://sigsum.org
上流ドキュメントhttps://sigsum.org
ライセンスBSD-2-Clause
ソースアーカイブhttps://git.glasklar.is/sigsum/core/sigsum-go/-/archive/v0.14.1/sigsum-go-v0.14.1.tar.bz2
最終更新2026-09-13T02:26:54Z
Pulseupdated
ビルド依存関係go
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesigsum-go
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Debian apt95%

golang-sigsum-sigsum-go-dev 0.11.2-1

tools for public and transparent logging of signed checksums (library)

https://git.glasklar.is/sigsum/core/sigsum-go

sudo apt install golang-sigsum-sigsum-go-dev
  • Section: golang
  • Architecture: all
  • Source Package: sigsum-go
  • normalized package name match
  • 一致条件: Sigsum Go
Debian stable package indexes · deb.debian.org · Debian stable package indexes: golang-sigsum-sigsum-go-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

sigsum-go 0.11.2-1+b3

tools for public and transparent logging of signed checksums

https://git.glasklar.is/sigsum/core/sigsum-go

sudo apt install sigsum-go
  • Section: golang
  • Architecture: amd64
  • Source Package: sigsum-go
  • 1 依存関係
  • normalized package name match
  • 一致条件: Sigsum Go
Debian stable package indexes · deb.debian.org · Debian stable package indexes: sigsum-go from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Ubuntu apt95%

golang-sigsum-sigsum-go-dev 0.7.2-2

tools for public and transparent logging of signed checksums (library)

https://www.sigsum.org/

sudo apt install golang-sigsum-sigsum-go-dev
  • Section: universe/golang
  • Architecture: all
  • Source Package: sigsum-go
  • normalized package name match
  • 一致条件: Sigsum Go
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: golang-sigsum-sigsum-go-dev from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
Ubuntu apt95%

sigsum-go 0.7.2-2

tools for public and transparent logging of signed checksums

https://www.sigsum.org/

sudo apt install sigsum-go
  • Section: universe/golang
  • Architecture: amd64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Sigsum Go
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: sigsum-go from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation