Sigstore 1.0.1
There is a newer prerelease version of this package available.
See the version list below for details.
See the version list below for details.
dotnet add package Sigstore --version 1.0.1
NuGet\Install-Package Sigstore -Version 1.0.1
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Sigstore" Version="1.0.1" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Sigstore" Version="1.0.1" />
<PackageReference Include="Sigstore" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Sigstore --version 1.0.1
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Sigstore, 1.0.1"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Sigstore@1.0.1
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Sigstore&version=1.0.1
#tool nuget:?package=Sigstore&version=1.0.1
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Sigstore
A .NET library for generating and verifying Sigstore signatures.
Overview
Sigstore is a pure .NET implementation of the Sigstore Client Specification. It supports keyless signing and verification using the Sigstore public good instance (Fulcio, Rekor, RFC 3161 TSA) — no external tools required.
Features
- Keyless signing — ephemeral ECDSA P-256 keys tied to OIDC identities
- Bundle verification — full Sigstore bundle verification (v0.1, v0.2, v0.3)
- Certificate validation — hybrid time model per RFC 5280
- Transparency log — Merkle inclusion proof and checkpoint verification
- RFC 3161 timestamps — timestamp authority integration
- DSSE attestations — in-toto statement signing and verification
- DI-friendly — constructor injection with sensible defaults
- AOT-compatible — fully trimmer and NativeAOT safe
Quick Start
Verification
using Sigstore;
var verifier = new SigstoreVerifier(trustRootProvider);
var policy = new VerificationPolicy
{
CertificateIdentity = CertificateIdentity.ForGitHubActions(
owner: "owner",
repository: "repo")
};
var result = await verifier.VerifyStreamAsync(artifactStream, bundle, policy);
Signing
var signer = new SigstoreSigner(fulcioClient, rekorClient, tsaClient, oidcProvider);
SigstoreBundle bundle = await signer.SignAsync(artifactStream);
string json = bundle.Serialize();
Bundle I/O
SigstoreBundle bundle = SigstoreBundle.Deserialize(json);
string json = bundle.Serialize();
Documentation
License
MIT — see LICENSE.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- BouncyCastle.Cryptography (>= 2.7.0)
- Tuf (>= 1.0.1)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Sigstore:
| Package | Downloads |
|---|---|
|
ActionsToolkit.Attest
This is an unofficial .NET SDK for GitHub Actions workflows (based on @actions/attest). |
GitHub repositories (1)
Showing the top 1 popular GitHub repositories that depend on Sigstore:
| Repository | Stars |
|---|---|
|
microsoft/aspire
Aspire is the tool for code-first, extensible, observable dev and deploy.
|
| Version | Downloads | Last Updated |
|---|---|---|
| 1.1.0-alpha.135.1.399a6e9 | 51 | 8/29/2026 |
| 1.1.0-alpha.131.1.fd8696f | 142 | 8/24/2026 |
| 1.1.0-alpha.129.1.d458555 | 61 | 8/24/2026 |
| 1.1.0-alpha.120.1.e78e1a9 | 54 | 8/22/2026 |
| 1.1.0-alpha.117.1.09281bc | 59 | 8/22/2026 |
| 1.1.0-alpha.111.1.15fc60d | 63 | 8/14/2026 |
| 1.1.0-alpha.108.1.d72863b | 61 | 8/14/2026 |
| 1.0.1 | 498 | 8/24/2026 |
| 1.0.1-beta.122.1.7bc133a | 109 | 8/22/2026 |
| 1.0.1-beta.112.1.de60e02 | 66 | 8/14/2026 |
| 1.0.1-beta.107.1.9ecbab6 | 55 | 8/14/2026 |
| 1.0.0 | 402 | 8/14/2026 |
| 1.0.0-beta.101.1.dd7cd33 | 75 | 8/14/2026 |
| 1.0.0-alpha.100.1.dd7cd33 | 108 | 8/13/2026 |
| 0.5.0 | 6,022 | 3/20/2026 |
| 0.4.0 | 734 | 3/11/2026 |
| 0.3.0 | 316 | 3/3/2026 |
| 0.2.0 | 169 | 3/3/2026 |