Continuous integration | Docs | License | Crate version | Crate downloads
----------------------|------|---------|---------------|-----------------
|
|
|
|
This is an experimental crate to interact with sigstore.
This is under high development, many features and checks are still missing.
The crate implements the following verification mechanisms:
Signature annotations and certificate email can be provided at verification time.
For use with Fulcio ephemeral key signing, an OpenID connect API is available.
All of the rekor client APIs can be leveraged.
The crate implements the following key interfaces:
The examples
directory contains demo programs using the library.
Each example can be executed with the cargo run --example <name>
command.
For example, the openidconnect
example can be run with the following command:
bash
cargo run --example openidconnect
Should you discover any security issues, please refer to sigstores security process