# 使用 Homebrew 安装 sigstore

查看 sigstore 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:sigstore
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install sigstore
```

  证据: local Homebrew formula metadata

## 软件包事实

- **软件包键:** brew:sigstore
- **软件包管理器:** Homebrew
- **软件包管理器页面:** <https://formulae.brew.sh/formula/sigstore>
- **版本:** 4.5.0
- **来源摘要:** Codesigning tool for Python packages
- **主页:** <https://github.com/sigstore/sigstore-python>
- **仓库:** <https://github.com/sigstore/sigstore-python>
- **许可证:** Apache-2.0
- **源码归档:** <https://files.pythonhosted.org/packages/18/e0/279419065e2d7102413605b3456122adbbccbc42e010b499c7b882fc01f8/sigstore-4.5.0.tar.gz>
- **最后更新:** 2026-07-29T10:17:13Z
- **已生成:** 2026-08-04T22:13:35+00:00

## 可执行文件

- sigstore (cli)
- sigstore (别名)

## 依赖

- certifi
- cryptography
- openssl@3
- pydantic
- python@3.14

## 构建依赖

- pkgconf
- rust

## 安装行为

- post-install 钩子: 未定义
- Bottle: 可用 于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## 版本和新鲜度

- 页面生成时间: 2026-08-04
- 管理器版本: 4.5.0
- 管理器更新时间: 2026-07-29
- 本地数据: OK
- 上游仓库: https://github.com/sigstore/sigstore-python
- 信息: No cached GitHub release or tag data was available.

## 安全说明

没有找到 sigstore 的匹配本地密钥处理 manifest。软件包元数据仍在此发布，以便未来覆盖拥有稳定的软件包 URL。


## 源数据库详情

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** sigstore
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable


## 相关链接

- [Source-control packages](https://pkg.so/zh-hans/source-control-tools/) - Belongs to a source-control command family.
- [Terminal utility packages](https://pkg.so/zh-hans/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Language runtime packages](https://pkg.so/zh-hans/language-runtime-packages/) - Matched language runtime, compiler, or interpreter metadata.
- [Networking and protocol packages](https://pkg.so/zh-hans/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [openssl@3](https://pkg.so/zh-hans/brew/openssl-3/) - Runtime dependency declared by Homebrew.
- [python@3.14](https://pkg.so/zh-hans/brew/python-3-14/) - Runtime dependency declared by Homebrew.
- [pkgconf](https://pkg.so/zh-hans/brew/pkgconf/) - Build dependency declared by Homebrew.
- [rust](https://pkg.so/zh-hans/brew/rust/) - Build dependency declared by Homebrew.
- [cosign](https://pkg.so/zh-hans/brew/cosign/) - Shares pkgdb curated category or tags: cli, security, sigstore, software-supply-chain, supply-chain-security.
- [safety](https://pkg.so/zh-hans/brew/safety/) - Shares pkgdb curated category or tags: cli, python, security, software-supply-chain, supply-chain-security.
- [rekor-cli](https://pkg.so/zh-hans/brew/rekor-cli/) - Shares pkgdb curated category or tags: cli, security, sigstore, software-supply-chain, supply-chain-security.
- [poutine](https://pkg.so/zh-hans/brew/poutine/) - Shares pkgdb curated category or tags: cli, security, software-supply-chain, supply-chain-security.
- [cyclonedx-python](https://pkg.so/zh-hans/brew/cyclonedx-python/) - Shares pkgdb curated category or tags: cli, python, security, software-supply-chain.
- [notation](https://pkg.so/zh-hans/brew/notation/) - Shares pkgdb curated category or tags: cli, security, software-supply-chain, supply-chain-security.
- [cve-bin-tool](https://pkg.so/zh-hans/brew/cve-bin-tool/) - Shares pkgdb curated category or tags: cli, python, security, software-supply-chain.
- [bomctl](https://pkg.so/zh-hans/brew/bomctl/) - Shares pkgdb curated category or tags: cli, security, software-supply-chain, supply-chain-security.

## Combined YAML source

View the package source record on GitHub. [combined/sigstore.yml](https://github.com/mxcl/pkgdb/blob/main/combined/sigstore.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- cross-ecosystem install command graph
