All integrations
Sigstore Rekor logo

Sigstore Rekor

Compliance & SecurityMonitoring

Look up software signatures in Sigstore's public transparency log: who signed a release, from which repository and commit, and prove the record is really there.

8 actions

Actions

Steps your workflow can run in Sigstore Rekor.

Find an artifact by its checksumCheck whether a file has been signed, and by whom. Paste its SHA-256 - the output of 'shasum -a 256', or the digest out of a container image reference - and this returns every entry in the public Sigstore log that signs it or attests to it, each one decoded down to who signed it, when, and for a build, which repository and commit it came from. Nothing found means the file was never signed with Sigstore, which is an answer worth having. No account or API key required.
Find what a signer has publishedSee everything one identity has signed. That identity is either an email address, for a person who signed interactively, or the identity URL of a build workflow - the form GitHub Actions uses, ending in the git ref the build ran on. Useful for watching a release pipeline: run it on a schedule and you will see what your own workflow published, and anything published in its name that you did not expect. No account or API key required.
Find what a signing key has publishedSee everything signed with one key, for projects that sign with their own key rather than with a Sigstore identity - PGP releases, SSH-signed tags, minisign, and packages from Alpine and RPM. Paste the public key and say which kind it is. Entries signed this way record that the key signed, not who holds it, which is the difference between key signing and Sigstore's keyless signing. No account or API key required.
Get a log entryRead one entry in full. Everything the log holds about it, decoded: what was signed, who signed it and who vouched for them, when the log accepted it, the whole signing certificate with the repository, commit, workflow run and runner behind it, and the entry's own record as the log stored it. Takes either the entry's identifier or its position in the log. No account or API key required.
Verify an entry is really in the logProve that a record is genuinely in the transparency log, rather than take the log's word for it. Three things are checked here, from the log's own published root hash: that the entry's contents match the identifier it was asked for, that hashing it together with its proof reproduces the root of the log's tree, and that the root the proof used is the one the log signed. Every check comes back with the numbers behind it. Use this before acting on a signature that matters. No account or API key required.
Get the log's current stateRead how big the public Sigstore log is right now, the root hash of its tree, the public key it signs with, and its checkpoint - the short signed statement of its size and root. Save that checkpoint. Handing it back to 'Check the log has not been rewritten' on a later run is what proves nothing published in between was altered or removed. No account or API key required.
Check the log has not been rewrittenProve that everything published before some earlier moment is still in the log, unchanged and in the same order. Paste the checkpoint that an earlier run of 'Get the log's current state' returned; this fetches the proof joining that moment to now and recomputes it. A transparency log is only trustworthy because somebody checks this, and almost nobody does - run it on a schedule and keep the newest checkpoint each time. No account or API key required.
List the newest entriesRead back from the newest entry in the log, newest first, to see what the world is signing right now - each one decoded down to who signed it and what. Filter by the kind of record, or ask only for entries added after some moment. The log takes roughly a hundred entries a second, so a step reads a bounded window of the newest ones and always says how far back it reached. No account or API key required.

Connect in a few clicks

Authenticate once and every action and trigger for the app is ready to drop into a workflow. No glue code, no maintenance.

Automate across your stack

Chain apps together with triggers, actions, and logic that move data between your tools automatically, so work happens without you.

Secure by default

Credentials are encrypted and scoped per workspace. Connect the tools your team already trusts with confidence.

Automate Sigstore Rekor with Lodol.

Connect Sigstore Rekor and build your first workflow in minutes. No credit card required.

Free plan available · No credit card required