{"id":369736,"url":"https://github.com/sigstore/sigstore-python","last_synced_at":"2026-05-31T19:30:42.068Z","repository":{"id":37481947,"uuid":"447691086","full_name":"sigstore/sigstore-python","owner":"sigstore","description":"A Sigstore client written in Python","archived":false,"fork":false,"pushed_at":"2026-05-23T08:38:17.000Z","size":3360,"stargazers_count":318,"open_issues_count":61,"forks_count":78,"subscribers_count":7,"default_branch":"main","last_synced_at":"2026-05-23T10:33:01.940Z","etag":null,"topics":["codesigning","python","security","supply-chain"],"latest_commit_sha":null,"homepage":"https://pypi.org/p/sigstore","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sigstore.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":"COPYRIGHT.txt","agents":null,"dco":null,"cla":null}},"created_at":"2022-01-13T17:29:37.000Z","updated_at":"2026-05-23T08:37:23.000Z","dependencies_parsed_at":"2023-12-16T22:39:38.394Z","dependency_job_id":"e360db1e-8743-4bb4-9bbe-1ba6f3453e55","html_url":"https://github.com/sigstore/sigstore-python","commit_stats":{"total_commits":853,"total_committers":36,"mean_commits":"23.694444444444443","dds":0.5275498241500587,"last_synced_commit":"cac62e8e611d4286a49ecda7f33d356381ab7919"},"previous_names":["trailofbits/pysign"],"tags_count":72,"template":false,"template_full_name":null,"purl":"pkg:github/sigstore/sigstore-python","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/sbom","scorecard":{"id":41071,"data":{"date":"2025-08-14T20:03:12Z","repo":{"name":"github.com/sigstore/sigstore-python","commit":"d1886a06b6db890512976999c980f9134cf605b4"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":8.4,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: test/assets/bundle_v3_github.whl:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:115","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:26","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:123","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:143","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards-analysis.yml:21","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards-analysis.yml:22","Warn: no topLevel permission defined: .github/workflows/check-embedded-root.yml:1","Info: found token with 'none' permissions: .github/workflows/ci.yml:1","Info: found token with 'none' permissions: .github/workflows/conformance.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/depsreview.yml:19","Info: found token with 'none' permissions: .github/workflows/docs.yml:1","Info: found token with 'none' permissions: .github/workflows/lint.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/pin-requirements.yml:19","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: found token with 'none' permissions: .github/workflows/requirements.yml:1","Info: found token with 'none' permissions: .github/workflows/scorecards-analysis.yml:1","Info: found token with 'none' permissions: .github/workflows/staging-tests.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/sigstore/sigstore-python/release.yml/main?enable=pin","Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:78","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:129","Warn: pipCommand not pinned by hash: .github/workflows/conformance.yml:28","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:81","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:82","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:29","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:45","Warn: pipCommand not pinned by hash: .github/workflows/requirements.yml:50","Warn: pipCommand not pinned by hash: .github/workflows/staging-tests.yml:43","Info:  38 out of  39 GitHub-owned GitHubAction dependencies pinned","Info:   8 out of   8 third-party GitHubAction dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned","Info:   0 out of   8 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v3.6.5 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945","Warn: release artifact v3.6.5 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":7,"reason":"SAST tool is not run on all commits -- score normalized to 7","details":["Warn: 21 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: OSSFuzz integration found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/sigstore/.github/SECURITY.md:1","Info: Found linked content: github.com/sigstore/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/sigstore/.github/SECURITY.md:1","Info: Found text in security policy: github.com/sigstore/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:103"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 34 contributing companies or organizations","details":["Info: found contributions from: GoogleCloudPlatform, Homebrew, PhillyPUG, UMD-CS-STICs, astral-sh, beedog, cea, cloudevents, cveda, disposable-email-domains, fabriccryptography, german-transcendental-idealism, google, googleapis, grinchrb, hexchat, imagen2, kbsecret, neurospin, ossf, psf, pypa, pypi, python, python-organizers, rlink7, sigstore, slsa-framework, theupdateframework, trailofbits, woodruffw-experiments, woodruffw-forks, woodruffw-hackathons, zizmorcore"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-14T21:33:32.362Z","repository_id":37481947,"created_at":"2025-08-14T21:33:32.362Z","updated_at":"2025-08-14T21:33:32.362Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33662198,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-29T02:00:06.066Z","response_time":107,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"owner":{"login":"sigstore","name":"sigstore","uuid":"71096353","kind":"organization","description":"Software Supply Chain Security","email":"info@sigstore.dev","website":"https://sigstore.dev","location":"United States of America","twitter":"projectsigstore","company":null,"icon_url":"https://avatars.githubusercontent.com/u/71096353?v=4","repositories_count":50,"last_synced_at":"2023-03-03T19:42:33.042Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/sigstore","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:04:40.320Z","updated_at":"2023-03-03T19:42:33.059Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore/repositories"},"packages":[{"id":12876950,"name":"python313Packages.sigstore","ecosystem":"nixpkgs","description":"Codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-01-27T04:51:44.737Z","latest_release_published_at":"2026-01-27T04:51:44.737Z","latest_release_number":"4.1.0","last_synced_at":"2026-05-14T14:03:37.930Z","created_at":"2026-01-27T04:51:44.493Z","updated_at":"2026-05-14T14:03:37.930Z","registry_url":"https://search.nixos.org/packages?channel=unstable\u0026query=python313Packages.sigstore","install_command":"nix-env -iA nixpkgs.python313Packages.sigstore","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-unstable/pkgs/development/python-modules/sigstore/default.nix#L106","metadata":{"nix_attribute":"python3.13-sigstore-4.1.0","position":"pkgs/development/python-modules/sigstore/default.nix:106","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","aarch64-darwin","aarch64-windows","x86_64-windows","i686-windows","i686-freebsd","x86_64-freebsd","aarch64-freebsd"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"],"upstream_ecosystem":"pypi","upstream_name":"sigstore","upstream_purl":"pkg:pypi/sigstore"},"repo_metadata":{},"repo_metadata_updated_at":null,"dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:nix/python313Packages.sigstore?channel=unstable","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/python313Packages.sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/python313Packages.sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/python313Packages.sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python313Packages.sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python313Packages.sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python313Packages.sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python313Packages.sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python313Packages.sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python313Packages.sigstore/codemeta","maintainers":[{"uuid":"Bot-wxt1221","login":null,"name":"Bot-wxt1221","email":"3264117476@qq.com","url":"https://github.com/Bot-wxt1221","packages_count":151,"html_url":null,"role":null,"created_at":"2026-03-07T06:26:24.446Z","updated_at":"2026-03-07T06:26:24.446Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers/Bot-wxt1221/packages"}],"registry":{"name":"nixpkgs-unstable","url":"https://channels.nixos.org/nixos-unstable","ecosystem":"nixpkgs","default":true,"packages_count":147106,"maintainers_count":4680,"namespaces_count":0,"keywords_count":2885,"github":"NixOS","metadata":{"funded_packages_count":1565},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:52.762Z","updated_at":"2026-05-15T05:01:34.865Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/namespaces"}},{"id":13089527,"name":"python312Packages.sigstore","ecosystem":"nixpkgs","description":"Codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-02-01T18:13:30.195Z","latest_release_published_at":"2026-02-01T18:13:30.195Z","latest_release_number":"2.1.5","last_synced_at":"2026-04-10T01:03:12.265Z","created_at":"2026-02-01T18:13:08.035Z","updated_at":"2026-04-10T01:32:14.739Z","registry_url":"https://search.nixos.org/packages?channel=24.11\u0026query=python312Packages.sigstore","install_command":"nix-env -iA nixpkgs.python312Packages.sigstore","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-24.11/pkgs/development/python-modules/sigstore/default.nix#L81","metadata":{"nix_attribute":"python3.12-sigstore-python-2.1.5","position":"pkgs/development/python-modules/sigstore/default.nix:81","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","i686-darwin","aarch64-darwin","armv7a-darwin","i686-cygwin","x86_64-cygwin","aarch64-windows","x86_64-windows","i686-windows","i686-freebsd","x86_64-freebsd"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"],"upstream_ecosystem":"pypi","upstream_name":"sigstore","upstream_purl":"pkg:pypi/sigstore"},"repo_metadata":{},"repo_metadata_updated_at":null,"dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:nix/python312Packages.sigstore?channel=24.11\u0026repository_url=https://channels.nixos.org/nixos-24.11","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/python312Packages.sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/python312Packages.sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/python312Packages.sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python312Packages.sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python312Packages.sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python312Packages.sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python312Packages.sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python312Packages.sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python312Packages.sigstore/codemeta","maintainers":[],"registry":{"name":"nixpkgs-24.11","url":"https://channels.nixos.org/nixos-24.11","ecosystem":"nixpkgs","default":false,"packages_count":121983,"maintainers_count":3777,"namespaces_count":0,"keywords_count":0,"github":"NixOS","metadata":{"funded_packages_count":228},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:53.059Z","updated_at":"2026-04-03T06:22:14.703Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/namespaces"}},{"id":13080677,"name":"python311Packages.sigstore","ecosystem":"nixpkgs","description":"Codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-02-01T17:47:56.831Z","latest_release_published_at":"2026-02-01T17:47:56.831Z","latest_release_number":"2.1.5","last_synced_at":"2026-03-05T04:18:18.246Z","created_at":"2026-02-01T17:47:30.645Z","updated_at":"2026-03-05T04:18:18.247Z","registry_url":"https://search.nixos.org/packages?channel=24.11\u0026query=python311Packages.sigstore","install_command":"nix-env -iA nixpkgs.python311Packages.sigstore","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-24.11/pkgs/development/python-modules/sigstore/default.nix#L81","metadata":{"nix_attribute":"python3.11-sigstore-python-2.1.5","position":"pkgs/development/python-modules/sigstore/default.nix:81","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","i686-darwin","aarch64-darwin","armv7a-darwin","i686-cygwin","x86_64-cygwin","aarch64-windows","x86_64-windows","i686-windows","i686-freebsd","x86_64-freebsd"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"],"upstream_ecosystem":"pypi","upstream_name":"sigstore","upstream_purl":"pkg:pypi/sigstore"},"repo_metadata":{},"repo_metadata_updated_at":null,"dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{},"purl":"pkg:nix/python311Packages.sigstore?channel=24.11\u0026repository_url=https://channels.nixos.org/nixos-24.11","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/python311Packages.sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/python311Packages.sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/python311Packages.sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python311Packages.sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python311Packages.sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python311Packages.sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python311Packages.sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python311Packages.sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/python311Packages.sigstore/codemeta","maintainers":[],"registry":{"name":"nixpkgs-24.11","url":"https://channels.nixos.org/nixos-24.11","ecosystem":"nixpkgs","default":false,"packages_count":121983,"maintainers_count":3777,"namespaces_count":0,"keywords_count":0,"github":"NixOS","metadata":{"funded_packages_count":228},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:53.059Z","updated_at":"2026-04-03T06:22:14.703Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/namespaces"}},{"id":13207731,"name":"python312Packages.sigstore","ecosystem":"nixpkgs","description":"A codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-02-02T01:11:49.953Z","latest_release_published_at":"2026-02-02T01:11:49.953Z","latest_release_number":"2.1.5","last_synced_at":"2026-03-07T14:07:09.435Z","created_at":"2026-02-02T01:11:45.271Z","updated_at":"2026-03-11T16:31:57.132Z","registry_url":"https://search.nixos.org/packages?channel=24.05\u0026query=python312Packages.sigstore","install_command":"nix-env -iA nixpkgs.python312Packages.sigstore","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-24.05/pkgs/development/python-modules/sigstore/default.nix#L81","metadata":{"nix_attribute":"python3.12-sigstore-python-2.1.5","position":"pkgs/development/python-modules/sigstore/default.nix:81","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","i686-darwin","aarch64-darwin","armv7a-darwin","i686-cygwin","x86_64-cygwin","x86_64-windows","i686-windows"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"],"upstream_ecosystem":"pypi","upstream_name":"sigstore","upstream_purl":"pkg:pypi/sigstore"},"repo_metadata":{},"repo_metadata_updated_at":null,"dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:nix/python312Packages.sigstore?channel=24.05\u0026repository_url=https://channels.nixos.org/nixos-24.05","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/python312Packages.sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/python312Packages.sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/python312Packages.sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python312Packages.sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python312Packages.sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python312Packages.sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python312Packages.sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python312Packages.sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python312Packages.sigstore/codemeta","maintainers":[],"registry":{"name":"nixpkgs-24.05","url":"https://channels.nixos.org/nixos-24.05","ecosystem":"nixpkgs","default":false,"packages_count":116156,"maintainers_count":3383,"namespaces_count":0,"keywords_count":654,"github":"NixOS","metadata":{"funded_packages_count":252},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:53.309Z","updated_at":"2026-05-29T05:10:13.988Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/namespaces"}},{"id":14513191,"name":"dev-python/sigstore","ecosystem":"gentoo","description":"A tool for signing Python package distributions","homepage":"https://github.com/sigstore/sigstore-python/","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["amd64","~ppc","~ppc64","~x86"],"namespace":"dev-python","versions_count":1,"first_release_published_at":"2026-05-11T16:39:47.000Z","latest_release_published_at":"2026-05-11T16:39:47.000Z","latest_release_number":"4.2.0","last_synced_at":"2026-05-27T02:38:45.271Z","created_at":"2026-05-27T02:38:44.993Z","updated_at":"2026-05-27T02:38:45.866Z","registry_url":"https://packages.gentoo.org/packages/dev-python/sigstore","install_command":"emerge dev-python/sigstore","documentation_url":"https://packages.gentoo.org/packages/dev-python/sigstore","metadata":{"category":"dev-python","slot":"0","eapi":"8","inherit":"distutils-r1","iuse":"test python_targets_python3_11 python_targets_python3_12 python_targets_python3_13 python_targets_python3_14"},"repo_metadata":{},"repo_metadata_updated_at":"2026-05-27T02:38:45.834Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:gentoo/dev-python/sigstore","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/gentoo/dev-python/sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/gentoo/dev-python/sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/gentoo/dev-python/sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages/dev-python%2Fsigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages/dev-python%2Fsigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages/dev-python%2Fsigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages/dev-python%2Fsigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages/dev-python%2Fsigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages/dev-python%2Fsigstore/codemeta","maintainers":[],"registry":{"name":"gentoo-portage","url":"https://packages.gentoo.org/","ecosystem":"gentoo","default":true,"packages_count":19292,"maintainers_count":0,"namespaces_count":174,"keywords_count":336,"github":"gentoo","metadata":{"snapshot_url":"https://distfiles.gentoo.org/snapshots/portage-latest.tar.xz","funded_packages_count":64},"icon_url":"https://github.com/gentoo.png","created_at":"2026-05-26T08:59:24.155Z","updated_at":"2026-05-31T05:04:07.013Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/gentoo-portage/namespaces"}},{"id":13199477,"name":"python311Packages.sigstore","ecosystem":"nixpkgs","description":"A codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-02-02T00:42:53.429Z","latest_release_published_at":"2026-02-02T00:42:53.429Z","latest_release_number":"2.1.5","last_synced_at":"2026-03-09T03:10:49.309Z","created_at":"2026-02-02T00:42:48.849Z","updated_at":"2026-03-09T13:02:21.805Z","registry_url":"https://search.nixos.org/packages?channel=24.05\u0026query=python311Packages.sigstore","install_command":"nix-env -iA nixpkgs.python311Packages.sigstore","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-24.05/pkgs/development/python-modules/sigstore/default.nix#L81","metadata":{"nix_attribute":"python3.11-sigstore-python-2.1.5","position":"pkgs/development/python-modules/sigstore/default.nix:81","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","i686-darwin","aarch64-darwin","armv7a-darwin","i686-cygwin","x86_64-cygwin","x86_64-windows","i686-windows"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"],"upstream_ecosystem":"pypi","upstream_name":"sigstore","upstream_purl":"pkg:pypi/sigstore"},"repo_metadata":{},"repo_metadata_updated_at":null,"dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:nix/python311Packages.sigstore?channel=24.05\u0026repository_url=https://channels.nixos.org/nixos-24.05","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/python311Packages.sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/python311Packages.sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/python311Packages.sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python311Packages.sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python311Packages.sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python311Packages.sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python311Packages.sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python311Packages.sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/python311Packages.sigstore/codemeta","maintainers":[],"registry":{"name":"nixpkgs-24.05","url":"https://channels.nixos.org/nixos-24.05","ecosystem":"nixpkgs","default":false,"packages_count":116156,"maintainers_count":3383,"namespaces_count":0,"keywords_count":654,"github":"NixOS","metadata":{"funded_packages_count":252},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:53.309Z","updated_at":"2026-05-29T05:10:13.988Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/namespaces"}},{"id":8493950,"name":"sigstore","ecosystem":"homebrew","description":"Codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":[],"namespace":null,"versions_count":21,"first_release_published_at":"2023-10-26T18:49:29.360Z","latest_release_published_at":"2026-02-03T01:35:12.952Z","latest_release_number":"4.2.0","last_synced_at":"2026-05-31T00:20:20.902Z","created_at":"2023-10-26T18:49:28.825Z","updated_at":"2026-05-31T00:20:21.008Z","registry_url":"https://formulae.brew.sh/formula/sigstore","install_command":"brew install sigstore","documentation_url":null,"metadata":{},"repo_metadata":{"id":37481947,"uuid":"447691086","full_name":"sigstore/sigstore-python","owner":"sigstore","description":"A Sigstore client written in Python","archived":false,"fork":false,"pushed_at":"2026-05-23T08:38:17.000Z","size":3360,"stargazers_count":318,"open_issues_count":61,"forks_count":78,"subscribers_count":7,"default_branch":"main","last_synced_at":"2026-05-23T10:33:01.940Z","etag":null,"topics":["codesigning","python","security","supply-chain"],"latest_commit_sha":null,"homepage":"https://pypi.org/p/sigstore","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sigstore.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":"COPYRIGHT.txt","agents":null,"dco":null,"cla":null}},"created_at":"2022-01-13T17:29:37.000Z","updated_at":"2026-05-23T08:37:23.000Z","dependencies_parsed_at":"2023-12-16T22:39:38.394Z","dependency_job_id":"e360db1e-8743-4bb4-9bbe-1ba6f3453e55","html_url":"https://github.com/sigstore/sigstore-python","commit_stats":{"total_commits":853,"total_committers":36,"mean_commits":"23.694444444444443","dds":0.5275498241500587,"last_synced_commit":"cac62e8e611d4286a49ecda7f33d356381ab7919"},"previous_names":["trailofbits/pysign"],"tags_count":72,"template":false,"template_full_name":null,"purl":"pkg:github/sigstore/sigstore-python","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/sbom","scorecard":{"id":41071,"data":{"date":"2025-08-14T20:03:12Z","repo":{"name":"github.com/sigstore/sigstore-python","commit":"d1886a06b6db890512976999c980f9134cf605b4"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":8.4,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: test/assets/bundle_v3_github.whl:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:115","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:26","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:123","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:143","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards-analysis.yml:21","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards-analysis.yml:22","Warn: no topLevel permission defined: .github/workflows/check-embedded-root.yml:1","Info: found token with 'none' permissions: .github/workflows/ci.yml:1","Info: found token with 'none' permissions: .github/workflows/conformance.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/depsreview.yml:19","Info: found token with 'none' permissions: .github/workflows/docs.yml:1","Info: found token with 'none' permissions: .github/workflows/lint.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/pin-requirements.yml:19","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: found token with 'none' permissions: .github/workflows/requirements.yml:1","Info: found token with 'none' permissions: .github/workflows/scorecards-analysis.yml:1","Info: found token with 'none' permissions: .github/workflows/staging-tests.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/sigstore/sigstore-python/release.yml/main?enable=pin","Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:78","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:129","Warn: pipCommand not pinned by hash: .github/workflows/conformance.yml:28","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:81","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:82","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:29","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:45","Warn: pipCommand not pinned by hash: .github/workflows/requirements.yml:50","Warn: pipCommand not pinned by hash: .github/workflows/staging-tests.yml:43","Info:  38 out of  39 GitHub-owned GitHubAction dependencies pinned","Info:   8 out of   8 third-party GitHubAction dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned","Info:   0 out of   8 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v3.6.5 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945","Warn: release artifact v3.6.5 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":7,"reason":"SAST tool is not run on all commits -- score normalized to 7","details":["Warn: 21 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: OSSFuzz integration found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/sigstore/.github/SECURITY.md:1","Info: Found linked content: github.com/sigstore/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/sigstore/.github/SECURITY.md:1","Info: Found text in security policy: github.com/sigstore/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:103"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 34 contributing companies or organizations","details":["Info: found contributions from: GoogleCloudPlatform, Homebrew, PhillyPUG, UMD-CS-STICs, astral-sh, beedog, cea, cloudevents, cveda, disposable-email-domains, fabriccryptography, german-transcendental-idealism, google, googleapis, grinchrb, hexchat, imagen2, kbsecret, neurospin, ossf, psf, pypa, pypi, python, python-organizers, rlink7, sigstore, slsa-framework, theupdateframework, trailofbits, woodruffw-experiments, woodruffw-forks, woodruffw-hackathons, zizmorcore"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-14T21:33:32.362Z","repository_id":37481947,"created_at":"2025-08-14T21:33:32.362Z","updated_at":"2025-08-14T21:33:32.362Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33662198,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-29T02:00:06.066Z","response_time":107,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"tags":[]},"repo_metadata_updated_at":"2026-05-31T00:20:21.008Z","dependent_packages_count":0,"downloads":46,"downloads_period":"last-month","dependent_repos_count":0,"rankings":{"downloads":64.81271282633371,"dependent_repos_count":56.82044002838893,"dependent_packages_count":19.580022701475595,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":47.07105851873274},"purl":"pkg:brew/sigstore","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/homebrew/sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/homebrew/sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/homebrew/sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-04-10T22:00:22.370Z","issues_count":362,"pull_requests_count":1608,"avg_time_to_close_issue":4443610.637931035,"avg_time_to_close_pull_request":307226.6109260493,"issues_closed_count":290,"pull_requests_closed_count":1501,"pull_request_authors_count":40,"issue_authors_count":53,"avg_comments_per_issue":2.6629834254143647,"avg_comments_per_pull_request":1.4875621890547264,"merged_pull_requests_count":1352,"bot_issues_count":75,"bot_pull_requests_count":930,"past_year_issues_count":67,"past_year_pull_requests_count":223,"past_year_avg_time_to_close_issue":744797.3636363636,"past_year_avg_time_to_close_pull_request":174583.7803468208,"past_year_issues_closed_count":33,"past_year_pull_requests_closed_count":173,"past_year_pull_request_authors_count":7,"past_year_issue_authors_count":11,"past_year_avg_comments_per_issue":1.373134328358209,"past_year_avg_comments_per_pull_request":1.3183856502242153,"past_year_bot_issues_count":6,"past_year_bot_pull_requests_count":126,"past_year_merged_pull_requests_count":158,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/issues","maintainers":[{"login":"woodruffw","count":401,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/woodruffw"},{"login":"jku","count":133,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jku"},{"login":"tetsuo-cpp","count":84,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tetsuo-cpp"},{"login":"di","count":65,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/di"},{"login":"tnytown","count":21,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tnytown"},{"login":"jleightcap","count":13,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jleightcap"},{"login":"DarkaMaul","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/DarkaMaul"},{"login":"bobcallaway","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bobcallaway"},{"login":"lukehinds","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lukehinds"},{"login":"mbestavros","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mbestavros"},{"login":"segiddins","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/segiddins"},{"login":"facutuesca","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/facutuesca"},{"login":"loosebazooka","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/loosebazooka"}],"active_maintainers":[{"login":"jku","count":78,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jku"},{"login":"woodruffw","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/woodruffw"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages/sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages/sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages/sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages/sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages/sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages/sigstore/codemeta","maintainers":[],"registry":{"name":"formulae.brew.sh","url":"https://formulae.brew.sh","ecosystem":"homebrew","default":true,"packages_count":9259,"maintainers_count":0,"namespaces_count":0,"keywords_count":0,"github":"homebrew","metadata":{"funded_packages_count":882},"icon_url":"https://github.com/homebrew.png","created_at":"2022-04-12T16:38:29.467Z","updated_at":"2026-04-03T06:49:13.885Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/formulae.brew.sh/namespaces"}},{"id":10361473,"name":"github.com/sigstore/sigstore-python","ecosystem":"go","description":null,"homepage":null,"licenses":"other","normalized_licenses":["Other"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":[],"namespace":null,"versions_count":62,"first_release_published_at":"2022-01-18T19:36:39.000Z","latest_release_published_at":"2026-01-26T14:52:51.000Z","latest_release_number":"v4.2.0+incompatible","last_synced_at":"2026-05-31T00:20:22.739Z","created_at":"2024-06-12T06:15:16.113Z","updated_at":"2026-05-31T00:20:22.739Z","registry_url":"https://pkg.go.dev/github.com/sigstore/sigstore-python","install_command":"go get github.com/sigstore/sigstore-python","documentation_url":"https://pkg.go.dev/github.com/sigstore/sigstore-python#section-documentation","metadata":{},"repo_metadata":{"id":37481947,"uuid":"447691086","full_name":"sigstore/sigstore-python","owner":"sigstore","description":"A Sigstore client written in Python","archived":false,"fork":false,"pushed_at":"2025-10-10T07:04:59.000Z","size":2674,"stargazers_count":295,"open_issues_count":48,"forks_count":63,"subscribers_count":8,"default_branch":"main","last_synced_at":"2025-10-10T18:15:36.542Z","etag":null,"topics":["codesigning","python","security","supply-chain"],"latest_commit_sha":null,"homepage":"https://pypi.org/p/sigstore","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sigstore.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":"COPYRIGHT.txt","agents":null,"dco":null,"cla":null}},"created_at":"2022-01-13T17:29:37.000Z","updated_at":"2025-10-10T07:05:02.000Z","dependencies_parsed_at":"2023-12-16T22:39:38.394Z","dependency_job_id":"e360db1e-8743-4bb4-9bbe-1ba6f3453e55","html_url":"https://github.com/sigstore/sigstore-python","commit_stats":{"total_commits":853,"total_committers":36,"mean_commits":"23.694444444444443","dds":0.5275498241500587,"last_synced_commit":"cac62e8e611d4286a49ecda7f33d356381ab7919"},"previous_names":["trailofbits/pysign"],"tags_count":65,"template":false,"template_full_name":null,"purl":"pkg:github/sigstore/sigstore-python","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/sbom","scorecard":{"id":41071,"data":{"date":"2025-08-14T20:03:12Z","repo":{"name":"github.com/sigstore/sigstore-python","commit":"d1886a06b6db890512976999c980f9134cf605b4"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":8.4,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: test/assets/bundle_v3_github.whl:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:115","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:26","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:123","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:143","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards-analysis.yml:21","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards-analysis.yml:22","Warn: no topLevel permission defined: .github/workflows/check-embedded-root.yml:1","Info: found token with 'none' permissions: .github/workflows/ci.yml:1","Info: found token with 'none' permissions: .github/workflows/conformance.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/depsreview.yml:19","Info: found token with 'none' permissions: .github/workflows/docs.yml:1","Info: found token with 'none' permissions: .github/workflows/lint.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/pin-requirements.yml:19","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: found token with 'none' permissions: .github/workflows/requirements.yml:1","Info: found token with 'none' permissions: .github/workflows/scorecards-analysis.yml:1","Info: found token with 'none' permissions: .github/workflows/staging-tests.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/sigstore/sigstore-python/release.yml/main?enable=pin","Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:78","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:129","Warn: pipCommand not pinned by hash: .github/workflows/conformance.yml:28","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:81","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:82","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:29","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:45","Warn: pipCommand not pinned by hash: .github/workflows/requirements.yml:50","Warn: pipCommand not pinned by hash: .github/workflows/staging-tests.yml:43","Info:  38 out of  39 GitHub-owned GitHubAction dependencies pinned","Info:   8 out of   8 third-party GitHubAction dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned","Info:   0 out of   8 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v3.6.5 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945","Warn: release artifact v3.6.5 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":7,"reason":"SAST tool is not run on all commits -- score normalized to 7","details":["Warn: 21 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: OSSFuzz integration found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/sigstore/.github/SECURITY.md:1","Info: Found linked content: github.com/sigstore/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/sigstore/.github/SECURITY.md:1","Info: Found text in security policy: github.com/sigstore/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:103"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 34 contributing companies or organizations","details":["Info: found contributions from: GoogleCloudPlatform, Homebrew, PhillyPUG, UMD-CS-STICs, astral-sh, beedog, cea, cloudevents, cveda, disposable-email-domains, fabriccryptography, german-transcendental-idealism, google, googleapis, grinchrb, hexchat, imagen2, kbsecret, neurospin, ossf, psf, pypa, pypi, python, python-organizers, rlink7, sigstore, slsa-framework, theupdateframework, trailofbits, woodruffw-experiments, woodruffw-forks, woodruffw-hackathons, zizmorcore"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-14T21:33:32.362Z","repository_id":37481947,"created_at":"2025-08-14T21:33:32.362Z","updated_at":"2025-08-14T21:33:32.362Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279006115,"owners_count":26084027,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-11T02:00:06.511Z","response_time":55,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"sigstore","name":"sigstore","uuid":"71096353","kind":"organization","description":"Software Supply Chain Security","email":"info@sigstore.dev","website":"https://sigstore.dev","location":"United States of America","twitter":"projectsigstore","company":null,"icon_url":"https://avatars.githubusercontent.com/u/71096353?v=4","repositories_count":50,"last_synced_at":"2023-03-03T19:42:33.042Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/sigstore","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:04:40.320Z","updated_at":"2023-03-03T19:42:33.059Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore/repositories"},"tags":[{"name":"v4.0.0","sha":"7a9551fe2efd45eb12cb873cfb8857427e33eb5a","kind":"commit","published_at":"2025-09-19T10:33:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v4.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v4.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v4.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.0.0/manifests"},{"name":"v3.6.5","sha":"447e66c7f8972ffe499d34fc6df68e63a0bb3028","kind":"commit","published_at":"2025-08-11T16:31:44.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.5/manifests"},{"name":"v3.6.4","sha":"dd952eb2e36ce9ae56f8db78c01c7fa6b15aab3e","kind":"commit","published_at":"2025-06-20T17:53:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.4/manifests"},{"name":"v3.6.3","sha":"0f889402b0c8f8fdfa8512dc6e3c23507b689f20","kind":"tag","published_at":"2025-06-06T06:06:14.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.3/manifests"},{"name":"v3.6.2","sha":"6937b05c3379fb6a3b23e47597a26e2cc72ababe","kind":"tag","published_at":"2025-04-14T07:36:57.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.2/manifests"},{"name":"v3.6.1","sha":"896cfe13105495e6dc6f8faf23e1007da35edeeb","kind":"commit","published_at":"2024-12-19T17:07:55.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.1/manifests"},{"name":"v3.6.0","sha":"44aa3ebe74cfce9fbc39bb5d771f3c2e5fb5daaf","kind":"commit","published_at":"2024-12-10T22:17:30.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.0/manifests"},{"name":"v3.5.3","sha":"87ff7f160d86a6eecf22160e7826a4de614ded49","kind":"commit","published_at":"2024-11-27T21:32:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.3/manifests"},{"name":"v3.5.2","sha":"276ed3d9bf8a9bd1d955eebcbf2fb6875e4591e8","kind":"commit","published_at":"2024-11-27T21:25:41.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.2/manifests"},{"name":"v3.5.1","sha":"0ac33eeaeb62ca466cef2708ca1dd5864382a008","kind":"commit","published_at":"2024-10-25T14:56:32.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.1/manifests"},{"name":"v3.5.0","sha":"68a7497e48f8c596b60ac7b67647d4299367c713","kind":"commit","published_at":"2024-10-24T16:01:16.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.0/manifests"},{"name":"v3.4.0","sha":"df51c7ab4d6773e3865e4d0194a2e1d117208273","kind":"commit","published_at":"2024-10-10T17:00:46.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.4.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.4.0/manifests"},{"name":"v3.3.0","sha":"343cbbf46e15160a6c483b24bb316ef20f2341d5","kind":"commit","published_at":"2024-09-18T15:00:57.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.3.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.3.0/manifests"},{"name":"v3.2.0","sha":"fc29ec190575ae345cea23f0953b64ca6f2ab8ba","kind":"commit","published_at":"2024-08-19T17:14:19.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.2.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.2.0/manifests"},{"name":"v3.1.0","sha":"3cda2b5f2498247754e650d51d7ef2ab1da4dc38","kind":"commit","published_at":"2024-07-31T21:04:30.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.1.0/manifests"},{"name":"v3.0.0","sha":"8578b545c2f8949211a185e5cf0ece7c17030a7a","kind":"commit","published_at":"2024-05-16T16:10:59.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0/manifests"},{"name":"v3.0.0rc2","sha":"3a19f8878a9659f40451560a01f14e2e9b5adb33","kind":"commit","published_at":"2024-05-07T16:12:27.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.0.0rc2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.0.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.0.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc2/manifests"},{"name":"v3.0.0rc1","sha":"d9965ca6c4a0ad260293a1d31eabb2996661ec9c","kind":"commit","published_at":"2024-05-02T15:19:54.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.0.0rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.0.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc1/manifests"},{"name":"v2.1.5","sha":"8e365d752bb51f8cb8e6244f85c90bc838ceee58","kind":"tag","published_at":"2024-04-08T14:22:36.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.5/manifests"},{"name":"v2.1.4","sha":"2edc752c231ed2c41e924886ddd7c8bce4fd9ed4","kind":"tag","published_at":"2024-04-08T11:18:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.4/manifests"},{"name":"v2.1.3","sha":"3c042244aaa1b69d7a868fed02ca57076c4721de","kind":"commit","published_at":"2024-03-19T17:25:32.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.3/manifests"},{"name":"v2.1.2","sha":"332f6d2e99a197616decd020163a5a9a53ab7f83","kind":"commit","published_at":"2024-02-04T10:22:29.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.2/manifests"},{"name":"v2.1.1","sha":"f99055fdad4ea1de8953b8f2c2cdcb93f00d11d6","kind":"commit","published_at":"2024-02-04T10:16:25.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"8ac00497f1f7674f42b25433e169f02039df8e08","kind":"commit","published_at":"2023-12-13T06:17:50.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.0/manifests"},{"name":"v2.0.1","sha":"2d6177d3bfa619b3e4de5cfc72a19caa0196b471","kind":"commit","published_at":"2023-10-17T20:33:13.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.1/manifests"},{"name":"v2.0.0","sha":"6c7069ea845f04ed2c6164a801b63af8b5d1be86","kind":"commit","published_at":"2023-09-28T18:34:48.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0/manifests"},{"name":"v2.0.0rc3","sha":"87681a9e7af3f71f30c5eedd1e696d2dda3513fd","kind":"commit","published_at":"2023-09-12T03:10:33.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0rc3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc3/manifests"},{"name":"v2.0.0rc2","sha":"0d0cef0221358793e13ce275cbae3a7bc7b11950","kind":"commit","published_at":"2023-07-21T19:09:58.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0rc2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc2/manifests"},{"name":"v2.0.0rc1","sha":"2c132f4f82bcb12faf16fcea9df944c724078977","kind":"commit","published_at":"2023-06-23T14:02:23.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc1/manifests"},{"name":"v1.1.2","sha":"f2123ba8f11a0b46481fe1927ababf2d4c612d91","kind":"commit","published_at":"2023-04-22T22:24:00.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2/manifests"},{"name":"v1.1.2rc1","sha":"c60f76e4ece5d469096b16b5d38e6dacd905cad4","kind":"commit","published_at":"2023-03-15T21:22:03.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.2rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.2rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.2rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2rc1/manifests"},{"name":"v1.1.1","sha":"b65f64140a334e2de468259dab8f058dc9fa0c3a","kind":"tag","published_at":"2023-03-06T22:11:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1/manifests"},{"name":"v1.1.1rc1","sha":"681018ca59e575dbef7cc679cd5efcbefd705541","kind":"tag","published_at":"2023-03-06T15:45:38.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.1rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1rc1/manifests"},{"name":"v1.1.0","sha":"c65f3d8e49a3762164321533ab0205d00360b652","kind":"tag","published_at":"2023-01-31T18:05:47.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.0/manifests"},{"name":"v1.0.0","sha":"55f98f663721be34a5e5b63fb72e740c3d580f66","kind":"tag","published_at":"2023-01-13T14:50:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0/manifests"},{"name":"v1.0.0rc1","sha":"d1a24e903d3b5d1690336330a9fd16e6c2560b5e","kind":"commit","published_at":"2023-01-12T00:48:07.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.0.0rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.0.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0rc1/manifests"},{"name":"v0.10.0","sha":"66581529803929c3ccc45334632ccd90f06e0de4","kind":"tag","published_at":"2023-01-09T19:45:58.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.10.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.10.0/manifests"},{"name":"v0.9.0","sha":"62865f364852c1842e4ccacc821e3190f9b92eb8","kind":"tag","published_at":"2022-12-22T16:32:46.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.9.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.9.0/manifests"},{"name":"v0.8.3","sha":"0bd51fd56de5f624198cbd5f9faf4f309c763ccf","kind":"tag","published_at":"2022-11-23T22:12:47.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"075f0467b8f841a58020611ec150ecb1a8db3ef5","kind":"tag","published_at":"2022-11-23T22:05:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"3b29ccb1c60fd229e3785952c6ffd16c606a942e","kind":"tag","published_at":"2022-11-23T21:59:20.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"d5506a6c8d8836342364a24af4027e4c4a454d1d","kind":"tag","published_at":"2022-11-23T21:38:50.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.0/manifests"},{"name":"v0.7.0","sha":"5410427e89653fe4344f72506d057f2872683f4c","kind":"tag","published_at":"2022-11-04T14:08:48.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.7.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.7.0/manifests"},{"name":"v0.6.8","sha":"2b7a574e60b8a08542d946c67e92f815355e83a7","kind":"tag","published_at":"2022-10-24T19:54:08.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.8","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"8ef54d8bb3ec89f1a582990024b55495605f1693","kind":"commit","published_at":"2022-10-11T18:29:57.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.7","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"2e438cd895e217b7e5c201832c6fd301619b5409","kind":"commit","published_at":"2022-10-05T00:45:34.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.6","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"4c8a5337c68315cf9d13410d379d0e9020631110","kind":"tag","published_at":"2022-09-15T20:55:39.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"566d34e2bfa8f8bf9dd781099d0d765cffb568d8","kind":"tag","published_at":"2022-09-08T17:35:34.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"bff2e635da74627b62b31efd746f533bf97801ed","kind":"commit","published_at":"2022-08-01T00:31:08.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"ea5cda9c29e6f9546e77a5b74517cf482b5d1a45","kind":"commit","published_at":"2022-06-21T20:57:11.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"dea9c08363b114c15d86008414f41f1b00dafac4","kind":"commit","published_at":"2022-06-10T18:48:06.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"7b763a6e1ab1a9f792fc4b18f78036016ea20fd5","kind":"commit","published_at":"2022-06-10T16:18:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.0/manifests"},{"name":"v0.5.1","sha":"05b7ab4de650271873469ef087273c28d1cac4d7","kind":"commit","published_at":"2022-06-06T19:01:00.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1/manifests"},{"name":"v0.5.1rc2","sha":"10ab4f9d179794c22a781e6fa72c0a57de6d4cac","kind":"commit","published_at":"2022-06-04T18:33:29.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.1rc2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.1rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.1rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc2/manifests"},{"name":"v0.5.1rc1","sha":"4d0c9f101309de49ae8f723488fb8c8247346ae7","kind":"commit","published_at":"2022-06-04T18:28:43.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.1rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc1/manifests"},{"name":"v0.5.0","sha":"a495ece800753d795fef311ebe8fea2f13e7ac68","kind":"commit","published_at":"2022-06-03T14:25:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.0/manifests"},{"name":"v0.4.2","sha":"dd2be1d19eeb0fbffbc36afe27bba7ba03fe97cf","kind":"commit","published_at":"2022-05-17T22:46:22.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.4.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"f2deb98e0c6080afe7c045047074a10e18cc3cd6","kind":"commit","published_at":"2022-05-11T16:53:25.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.4.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"457ddfab0356f71c8d790bb5cea66956a632fd0a","kind":"commit","published_at":"2022-05-10T21:06:15.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.4.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.0/manifests"},{"name":"v0.3.1","sha":"177e415a46fb16cc87fa1657067f8dead1eba384","kind":"commit","published_at":"2022-05-02T23:08:01.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.3.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"3dfc786b27ad831546bb85c84420efdb96f064db","kind":"commit","published_at":"2022-05-02T23:04:48.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.3.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.0/manifests"},{"name":"v0.2.0","sha":"1af4b824e3bc36fbe8e400f77c224b1a939b639a","kind":"commit","published_at":"2022-04-30T06:16:43.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.2.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.2.0/manifests"},{"name":"v0.1.0","sha":"d3d463f65fb4b2c4ceb7e8446855e9b47dcd959f","kind":"commit","published_at":"2022-04-29T22:14:54.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.1.0/manifests"},{"name":"v0.0.1-pre.3","sha":"0fc52e3345e758db6119577fca05a75fa79f44c6","kind":"commit","published_at":"2022-04-28T22:46:28.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.0.1-pre.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.0.1-pre.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.0.1-pre.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.3/manifests"},{"name":"v0.0.1-pre.1","sha":"7fb389549650eb0c52b090db6393bd44f60a3583","kind":"commit","published_at":"2022-01-18T19:36:39.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.0.1-pre.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.0.1-pre.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.0.1-pre.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.1/manifests"}]},"repo_metadata_updated_at":"2025-10-12T08:24:05.012Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":6.958767526308751,"dependent_packages_count":6.520931273209822,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":6.7398493997592865},"purl":"pkg:golang/github.com/sigstore/sigstore-python","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/sigstore/sigstore-python","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/sigstore/sigstore-python","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/sigstore/sigstore-python/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2025-10-07T22:00:58.532Z","issues_count":354,"pull_requests_count":1574,"avg_time_to_close_issue":4513262.119298246,"avg_time_to_close_pull_request":317448.1323828921,"issues_closed_count":285,"pull_requests_closed_count":1473,"pull_request_authors_count":39,"issue_authors_count":52,"avg_comments_per_issue":2.6836158192090394,"avg_comments_per_pull_request":1.5063532401524777,"merged_pull_requests_count":1325,"bot_issues_count":73,"bot_pull_requests_count":905,"past_year_issues_count":86,"past_year_pull_requests_count":484,"past_year_avg_time_to_close_issue":1210846.4444444445,"past_year_avg_time_to_close_pull_request":171172.427184466,"past_year_issues_closed_count":45,"past_year_pull_requests_closed_count":412,"past_year_pull_request_authors_count":11,"past_year_issue_authors_count":22,"past_year_avg_comments_per_issue":1.372093023255814,"past_year_avg_comments_per_pull_request":1.2851239669421488,"past_year_bot_issues_count":9,"past_year_bot_pull_requests_count":311,"past_year_merged_pull_requests_count":363,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/issues","maintainers":[{"login":"woodruffw","count":401,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/woodruffw"},{"login":"jku","count":121,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jku"},{"login":"tetsuo-cpp","count":84,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tetsuo-cpp"},{"login":"di","count":65,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/di"},{"login":"tnytown","count":21,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tnytown"},{"login":"jleightcap","count":13,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jleightcap"},{"login":"DarkaMaul","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/DarkaMaul"},{"login":"bobcallaway","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bobcallaway"},{"login":"lukehinds","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lukehinds"},{"login":"mbestavros","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mbestavros"},{"login":"segiddins","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/segiddins"},{"login":"facutuesca","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/facutuesca"},{"login":"loosebazooka","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/loosebazooka"}],"active_maintainers":[{"login":"jku","count":83,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jku"},{"login":"woodruffw","count":57,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/woodruffw"},{"login":"DarkaMaul","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/DarkaMaul"},{"login":"di","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/di"},{"login":"facutuesca","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/facutuesca"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fsigstore%2Fsigstore-python/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fsigstore%2Fsigstore-python/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fsigstore%2Fsigstore-python/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fsigstore%2Fsigstore-python/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fsigstore%2Fsigstore-python/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fsigstore%2Fsigstore-python/codemeta","maintainers":[],"registry":{"name":"proxy.golang.org","url":"https://proxy.golang.org","ecosystem":"go","default":true,"packages_count":2153818,"maintainers_count":0,"namespaces_count":782439,"keywords_count":112823,"github":"golang","metadata":{"funded_packages_count":53495},"icon_url":"https://github.com/golang.png","created_at":"2022-04-04T15:19:22.939Z","updated_at":"2026-04-19T05:14:45.920Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/namespaces"}},{"id":12900703,"name":"python314Packages.sigstore","ecosystem":"nixpkgs","description":"Codesigning tool for Python packages","homepage":"https://github.com/sigstore/sigstore-python","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-01-27T10:17:37.815Z","latest_release_published_at":"2026-01-27T10:17:37.815Z","latest_release_number":"4.1.0","last_synced_at":"2026-03-07T19:22:03.723Z","created_at":"2026-01-27T10:17:37.260Z","updated_at":"2026-03-10T23:32:19.062Z","registry_url":"https://search.nixos.org/packages?channel=unstable\u0026query=python314Packages.sigstore","install_command":"nix-env -iA nixpkgs.python314Packages.sigstore","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-unstable/pkgs/development/python-modules/sigstore/default.nix#L106","metadata":{"nix_attribute":"python3.14-sigstore-4.1.0","position":"pkgs/development/python-modules/sigstore/default.nix:106","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","aarch64-darwin","aarch64-windows","x86_64-windows","i686-windows","i686-freebsd","x86_64-freebsd","aarch64-freebsd"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"],"upstream_ecosystem":"pypi","upstream_name":"sigstore","upstream_purl":"pkg:pypi/sigstore"},"repo_metadata":{},"repo_metadata_updated_at":null,"dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:nix/python314Packages.sigstore?channel=unstable","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/python314Packages.sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/python314Packages.sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/python314Packages.sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python314Packages.sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python314Packages.sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python314Packages.sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python314Packages.sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python314Packages.sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/python314Packages.sigstore/codemeta","maintainers":[{"uuid":"Bot-wxt1221","login":null,"name":"Bot-wxt1221","email":"3264117476@qq.com","url":"https://github.com/Bot-wxt1221","packages_count":151,"html_url":null,"role":null,"created_at":"2026-03-07T19:22:03.891Z","updated_at":"2026-03-07T19:22:03.891Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers/Bot-wxt1221/packages"}],"registry":{"name":"nixpkgs-unstable","url":"https://channels.nixos.org/nixos-unstable","ecosystem":"nixpkgs","default":true,"packages_count":147106,"maintainers_count":4680,"namespaces_count":0,"keywords_count":2885,"github":"NixOS","metadata":{"funded_packages_count":1565},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:52.762Z","updated_at":"2026-05-15T05:01:34.865Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/namespaces"}},{"id":4340240,"name":"sigstore","ecosystem":"pypi","description":"A tool for signing Python package distributions","homepage":"https://pypi.org/project/sigstore/","licenses":"Apache Software License","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/sigstore/sigstore-python","keywords_array":[],"namespace":null,"versions_count":63,"first_release_published_at":"2022-04-28T16:53:13.000Z","latest_release_published_at":"2026-01-26T15:01:33.000Z","latest_release_number":"4.2.0","last_synced_at":"2026-05-31T13:43:39.775Z","created_at":"2022-04-28T17:01:45.392Z","updated_at":"2026-05-31T19:12:11.410Z","registry_url":"https://pypi.org/project/sigstore/","install_command":"pip install sigstore --index-url https://pypi.org/simple","documentation_url":"https://sigstore.github.io/sigstore-python/","metadata":{"funding":null,"documentation":"https://sigstore.github.io/sigstore-python/","classifiers":["Development Status :: 5 - Production/Stable","Intended Audience :: Developers","License :: OSI Approved :: Apache Software License","Programming Language :: Python :: 3","Programming Language :: Python :: 3 :: Only","Programming Language :: Python :: 3.10","Programming Language :: Python :: 3.11","Programming Language :: Python :: 3.12","Programming Language :: Python :: 3.13","Programming Language :: Python :: 3.14","Topic :: Security","Topic :: Security :: Cryptography"],"normalized_name":"sigstore","project_status":null},"repo_metadata":{"id":37481947,"uuid":"447691086","full_name":"sigstore/sigstore-python","owner":"sigstore","description":"A Sigstore client written in Python","archived":false,"fork":false,"pushed_at":"2026-04-21T14:02:28.000Z","size":3078,"stargazers_count":317,"open_issues_count":55,"forks_count":75,"subscribers_count":7,"default_branch":"main","last_synced_at":"2026-04-22T20:10:23.268Z","etag":null,"topics":["codesigning","python","security","supply-chain"],"latest_commit_sha":null,"homepage":"https://pypi.org/p/sigstore","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sigstore.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":"COPYRIGHT.txt","agents":null,"dco":null,"cla":null}},"created_at":"2022-01-13T17:29:37.000Z","updated_at":"2026-04-21T14:02:31.000Z","dependencies_parsed_at":"2023-12-16T22:39:38.394Z","dependency_job_id":"e360db1e-8743-4bb4-9bbe-1ba6f3453e55","html_url":"https://github.com/sigstore/sigstore-python","commit_stats":{"total_commits":853,"total_committers":36,"mean_commits":"23.694444444444443","dds":0.5275498241500587,"last_synced_commit":"cac62e8e611d4286a49ecda7f33d356381ab7919"},"previous_names":["trailofbits/pysign"],"tags_count":72,"template":false,"template_full_name":null,"purl":"pkg:github/sigstore/sigstore-python","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/sbom","scorecard":{"id":41071,"data":{"date":"2025-08-14T20:03:12Z","repo":{"name":"github.com/sigstore/sigstore-python","commit":"d1886a06b6db890512976999c980f9134cf605b4"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":8.4,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: test/assets/bundle_v3_github.whl:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:115","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/pin-requirements.yml:26","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:123","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:143","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards-analysis.yml:21","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards-analysis.yml:22","Warn: no topLevel permission defined: .github/workflows/check-embedded-root.yml:1","Info: found token with 'none' permissions: .github/workflows/ci.yml:1","Info: found token with 'none' permissions: .github/workflows/conformance.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/depsreview.yml:19","Info: found token with 'none' permissions: .github/workflows/docs.yml:1","Info: found token with 'none' permissions: .github/workflows/lint.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/pin-requirements.yml:19","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: found token with 'none' permissions: .github/workflows/requirements.yml:1","Info: found token with 'none' permissions: .github/workflows/scorecards-analysis.yml:1","Info: found token with 'none' permissions: .github/workflows/staging-tests.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/sigstore/sigstore-python/release.yml/main?enable=pin","Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:78","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:129","Warn: pipCommand not pinned by hash: .github/workflows/conformance.yml:28","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:81","Warn: pipCommand not pinned by hash: .github/workflows/pin-requirements.yml:82","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:29","Warn: pipCommand not pinned by hash: .github/workflows/release.yml:45","Warn: pipCommand not pinned by hash: .github/workflows/requirements.yml:50","Warn: pipCommand not pinned by hash: .github/workflows/staging-tests.yml:43","Info:  38 out of  39 GitHub-owned GitHubAction dependencies pinned","Info:   8 out of   8 third-party GitHubAction dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned","Info:   0 out of   8 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v3.6.5 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 not signed: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945","Warn: release artifact v3.6.5 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/239122716","Warn: release artifact v3.6.4 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/226757436","Warn: release artifact v3.6.3 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/223560840","Warn: release artifact v3.6.2 does not have provenance: https://api.github.com/repos/sigstore/sigstore-python/releases/212131945"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":7,"reason":"SAST tool is not run on all commits -- score normalized to 7","details":["Warn: 21 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: OSSFuzz integration found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/sigstore/.github/SECURITY.md:1","Info: Found linked content: github.com/sigstore/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/sigstore/.github/SECURITY.md:1","Info: Found text in security policy: github.com/sigstore/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:103"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 34 contributing companies or organizations","details":["Info: found contributions from: GoogleCloudPlatform, Homebrew, PhillyPUG, UMD-CS-STICs, astral-sh, beedog, cea, cloudevents, cveda, disposable-email-domains, fabriccryptography, german-transcendental-idealism, google, googleapis, grinchrb, hexchat, imagen2, kbsecret, neurospin, ossf, psf, pypa, pypi, python, python-organizers, rlink7, sigstore, slsa-framework, theupdateframework, trailofbits, woodruffw-experiments, woodruffw-forks, woodruffw-hackathons, zizmorcore"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-08-14T21:33:32.362Z","repository_id":37481947,"created_at":"2025-08-14T21:33:32.362Z","updated_at":"2025-08-14T21:33:32.362Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32320761,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-26T23:26:28.701Z","status":"online","status_checked_at":"2026-04-27T02:00:06.769Z","response_time":128,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"sigstore","name":"sigstore","uuid":"71096353","kind":"organization","description":"Software Supply Chain Security","email":"info@sigstore.dev","website":"https://sigstore.dev","location":"United States of America","twitter":"projectsigstore","company":null,"icon_url":"https://avatars.githubusercontent.com/u/71096353?v=4","repositories_count":50,"last_synced_at":"2023-03-03T19:42:33.042Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/sigstore","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:04:40.320Z","updated_at":"2023-03-03T19:42:33.059Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sigstore/repositories"},"tags":[{"name":"v3.6.7","sha":"2cb4a174e6f4b270e313aa60704a48223e61c912","kind":"commit","published_at":"2026-01-26T15:01:00.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.7","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.7/manifests"},{"name":"v4.2.0","sha":"94818e43224db2aed78f3cf066a561cf95982051","kind":"commit","published_at":"2026-01-26T14:52:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v4.2.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v4.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v4.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.2.0/manifests"},{"name":"v3.5.6","sha":"b91c7a9543920a9e93aa863c69f6e10389aacded","kind":"commit","published_at":"2025-10-27T13:39:16.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.6","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.6/manifests"},{"name":"v3.5.5","sha":"bda83b892669c198cb7b1191184fbede29b17c04","kind":"commit","published_at":"2025-10-25T11:25:49.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.5/manifests"},{"name":"v3.5.4","sha":"2a8d5b9306ddc886ef60d933ac6c21c5f5f5b1d7","kind":"commit","published_at":"2025-10-24T07:22:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.4/manifests"},{"name":"v4.1.0","sha":"3447f9603cfa0e9fe9d9c83d5bd5fb0bfe08a598","kind":"commit","published_at":"2025-10-11T12:45:22.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v4.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v4.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v4.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.1.0/manifests"},{"name":"v3.6.6","sha":"2a5e4e44d94d211de61396fc8c20a3b18cde1966","kind":"commit","published_at":"2025-10-08T08:11:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.6","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.6/manifests"},{"name":"v4.0.0","sha":"7a9551fe2efd45eb12cb873cfb8857427e33eb5a","kind":"commit","published_at":"2025-09-19T10:33:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v4.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v4.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v4.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v4.0.0/manifests"},{"name":"v3.6.5","sha":"447e66c7f8972ffe499d34fc6df68e63a0bb3028","kind":"commit","published_at":"2025-08-11T16:31:44.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.5/manifests"},{"name":"v3.6.4","sha":"dd952eb2e36ce9ae56f8db78c01c7fa6b15aab3e","kind":"commit","published_at":"2025-06-20T17:53:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.4/manifests"},{"name":"v3.6.3","sha":"0f889402b0c8f8fdfa8512dc6e3c23507b689f20","kind":"tag","published_at":"2025-06-06T06:06:14.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.3/manifests"},{"name":"v3.6.2","sha":"6937b05c3379fb6a3b23e47597a26e2cc72ababe","kind":"tag","published_at":"2025-04-14T07:36:57.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.2/manifests"},{"name":"v3.6.1","sha":"896cfe13105495e6dc6f8faf23e1007da35edeeb","kind":"commit","published_at":"2024-12-19T17:07:55.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.1/manifests"},{"name":"v3.6.0","sha":"44aa3ebe74cfce9fbc39bb5d771f3c2e5fb5daaf","kind":"commit","published_at":"2024-12-10T22:17:30.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.6.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.6.0/manifests"},{"name":"v3.5.3","sha":"87ff7f160d86a6eecf22160e7826a4de614ded49","kind":"commit","published_at":"2024-11-27T21:32:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.3/manifests"},{"name":"v3.5.2","sha":"276ed3d9bf8a9bd1d955eebcbf2fb6875e4591e8","kind":"commit","published_at":"2024-11-27T21:25:41.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.2/manifests"},{"name":"v3.5.1","sha":"0ac33eeaeb62ca466cef2708ca1dd5864382a008","kind":"commit","published_at":"2024-10-25T14:56:32.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.1/manifests"},{"name":"v3.5.0","sha":"68a7497e48f8c596b60ac7b67647d4299367c713","kind":"commit","published_at":"2024-10-24T16:01:16.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.5.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.5.0/manifests"},{"name":"v3.4.0","sha":"df51c7ab4d6773e3865e4d0194a2e1d117208273","kind":"commit","published_at":"2024-10-10T17:00:46.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.4.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.4.0/manifests"},{"name":"v3.3.0","sha":"343cbbf46e15160a6c483b24bb316ef20f2341d5","kind":"commit","published_at":"2024-09-18T15:00:57.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.3.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.3.0/manifests"},{"name":"v3.2.0","sha":"fc29ec190575ae345cea23f0953b64ca6f2ab8ba","kind":"commit","published_at":"2024-08-19T17:14:19.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.2.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.2.0/manifests"},{"name":"v3.1.0","sha":"3cda2b5f2498247754e650d51d7ef2ab1da4dc38","kind":"commit","published_at":"2024-07-31T21:04:30.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.1.0/manifests"},{"name":"v3.0.0","sha":"8578b545c2f8949211a185e5cf0ece7c17030a7a","kind":"commit","published_at":"2024-05-16T16:10:59.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0/manifests"},{"name":"v3.0.0rc2","sha":"3a19f8878a9659f40451560a01f14e2e9b5adb33","kind":"commit","published_at":"2024-05-07T16:12:27.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.0.0rc2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.0.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.0.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc2/manifests"},{"name":"v3.0.0rc1","sha":"d9965ca6c4a0ad260293a1d31eabb2996661ec9c","kind":"commit","published_at":"2024-05-02T15:19:54.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v3.0.0rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v3.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v3.0.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v3.0.0rc1/manifests"},{"name":"v2.1.5","sha":"8e365d752bb51f8cb8e6244f85c90bc838ceee58","kind":"tag","published_at":"2024-04-08T14:22:36.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.5/manifests"},{"name":"v2.1.4","sha":"2edc752c231ed2c41e924886ddd7c8bce4fd9ed4","kind":"tag","published_at":"2024-04-08T11:18:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.4/manifests"},{"name":"v2.1.3","sha":"3c042244aaa1b69d7a868fed02ca57076c4721de","kind":"commit","published_at":"2024-03-19T17:25:32.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.3/manifests"},{"name":"v2.1.2","sha":"332f6d2e99a197616decd020163a5a9a53ab7f83","kind":"commit","published_at":"2024-02-04T10:22:29.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.2/manifests"},{"name":"v2.1.1","sha":"f99055fdad4ea1de8953b8f2c2cdcb93f00d11d6","kind":"commit","published_at":"2024-02-04T10:16:25.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"8ac00497f1f7674f42b25433e169f02039df8e08","kind":"commit","published_at":"2023-12-13T06:17:50.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.1.0/manifests"},{"name":"v2.0.1","sha":"2d6177d3bfa619b3e4de5cfc72a19caa0196b471","kind":"commit","published_at":"2023-10-17T20:33:13.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.1/manifests"},{"name":"v2.0.0","sha":"6c7069ea845f04ed2c6164a801b63af8b5d1be86","kind":"commit","published_at":"2023-09-28T18:34:48.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0/manifests"},{"name":"v2.0.0rc3","sha":"87681a9e7af3f71f30c5eedd1e696d2dda3513fd","kind":"commit","published_at":"2023-09-12T03:10:33.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0rc3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0rc3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0rc3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc3/manifests"},{"name":"v2.0.0rc2","sha":"0d0cef0221358793e13ce275cbae3a7bc7b11950","kind":"commit","published_at":"2023-07-21T19:09:58.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0rc2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc2/manifests"},{"name":"v2.0.0rc1","sha":"2c132f4f82bcb12faf16fcea9df944c724078977","kind":"commit","published_at":"2023-06-23T14:02:23.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v2.0.0rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v2.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v2.0.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v2.0.0rc1/manifests"},{"name":"v1.1.2","sha":"f2123ba8f11a0b46481fe1927ababf2d4c612d91","kind":"commit","published_at":"2023-04-22T22:24:00.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2/manifests"},{"name":"v1.1.2rc1","sha":"c60f76e4ece5d469096b16b5d38e6dacd905cad4","kind":"commit","published_at":"2023-03-15T21:22:03.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.2rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.2rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.2rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.2rc1/manifests"},{"name":"v1.1.1","sha":"b65f64140a334e2de468259dab8f058dc9fa0c3a","kind":"tag","published_at":"2023-03-06T22:11:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1/manifests"},{"name":"v1.1.1rc1","sha":"681018ca59e575dbef7cc679cd5efcbefd705541","kind":"tag","published_at":"2023-03-06T15:45:38.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.1rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.1rc1/manifests"},{"name":"v1.1.0","sha":"c65f3d8e49a3762164321533ab0205d00360b652","kind":"tag","published_at":"2023-01-31T18:05:47.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.1.0/manifests"},{"name":"v1.0.0","sha":"55f98f663721be34a5e5b63fb72e740c3d580f66","kind":"tag","published_at":"2023-01-13T14:50:51.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.0.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0/manifests"},{"name":"v1.0.0rc1","sha":"d1a24e903d3b5d1690336330a9fd16e6c2560b5e","kind":"commit","published_at":"2023-01-12T00:48:07.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v1.0.0rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v1.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v1.0.0rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v1.0.0rc1/manifests"},{"name":"v0.10.0","sha":"66581529803929c3ccc45334632ccd90f06e0de4","kind":"tag","published_at":"2023-01-09T19:45:58.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.10.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.10.0/manifests"},{"name":"v0.9.0","sha":"62865f364852c1842e4ccacc821e3190f9b92eb8","kind":"tag","published_at":"2022-12-22T16:32:46.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.9.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.9.0/manifests"},{"name":"v0.8.3","sha":"0bd51fd56de5f624198cbd5f9faf4f309c763ccf","kind":"tag","published_at":"2022-11-23T22:12:47.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"075f0467b8f841a58020611ec150ecb1a8db3ef5","kind":"tag","published_at":"2022-11-23T22:05:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"3b29ccb1c60fd229e3785952c6ffd16c606a942e","kind":"tag","published_at":"2022-11-23T21:59:20.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"d5506a6c8d8836342364a24af4027e4c4a454d1d","kind":"tag","published_at":"2022-11-23T21:38:50.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.8.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.8.0/manifests"},{"name":"v0.7.0","sha":"5410427e89653fe4344f72506d057f2872683f4c","kind":"tag","published_at":"2022-11-04T14:08:48.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.7.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.7.0/manifests"},{"name":"v0.6.8","sha":"2b7a574e60b8a08542d946c67e92f815355e83a7","kind":"tag","published_at":"2022-10-24T19:54:08.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.8","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"8ef54d8bb3ec89f1a582990024b55495605f1693","kind":"commit","published_at":"2022-10-11T18:29:57.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.7","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"2e438cd895e217b7e5c201832c6fd301619b5409","kind":"commit","published_at":"2022-10-05T00:45:34.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.6","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"4c8a5337c68315cf9d13410d379d0e9020631110","kind":"tag","published_at":"2022-09-15T20:55:39.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.5","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"566d34e2bfa8f8bf9dd781099d0d765cffb568d8","kind":"tag","published_at":"2022-09-08T17:35:34.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.4","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"bff2e635da74627b62b31efd746f533bf97801ed","kind":"commit","published_at":"2022-08-01T00:31:08.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"ea5cda9c29e6f9546e77a5b74517cf482b5d1a45","kind":"commit","published_at":"2022-06-21T20:57:11.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"dea9c08363b114c15d86008414f41f1b00dafac4","kind":"commit","published_at":"2022-06-10T18:48:06.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"7b763a6e1ab1a9f792fc4b18f78036016ea20fd5","kind":"commit","published_at":"2022-06-10T16:18:12.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.6.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.6.0/manifests"},{"name":"v0.5.1","sha":"05b7ab4de650271873469ef087273c28d1cac4d7","kind":"commit","published_at":"2022-06-06T19:01:00.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1/manifests"},{"name":"v0.5.1rc2","sha":"10ab4f9d179794c22a781e6fa72c0a57de6d4cac","kind":"commit","published_at":"2022-06-04T18:33:29.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.1rc2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.1rc2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.1rc2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc2/manifests"},{"name":"v0.5.1rc1","sha":"4d0c9f101309de49ae8f723488fb8c8247346ae7","kind":"commit","published_at":"2022-06-04T18:28:43.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.1rc1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.1rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.1rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.1rc1/manifests"},{"name":"v0.5.0","sha":"a495ece800753d795fef311ebe8fea2f13e7ac68","kind":"commit","published_at":"2022-06-03T14:25:35.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.5.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.5.0/manifests"},{"name":"v0.4.2","sha":"dd2be1d19eeb0fbffbc36afe27bba7ba03fe97cf","kind":"commit","published_at":"2022-05-17T22:46:22.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.4.2","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"f2deb98e0c6080afe7c045047074a10e18cc3cd6","kind":"commit","published_at":"2022-05-11T16:53:25.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.4.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"457ddfab0356f71c8d790bb5cea66956a632fd0a","kind":"commit","published_at":"2022-05-10T21:06:15.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.4.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.4.0/manifests"},{"name":"v0.3.1","sha":"177e415a46fb16cc87fa1657067f8dead1eba384","kind":"commit","published_at":"2022-05-02T23:08:01.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.3.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"3dfc786b27ad831546bb85c84420efdb96f064db","kind":"commit","published_at":"2022-05-02T23:04:48.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.3.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.3.0/manifests"},{"name":"v0.2.0","sha":"1af4b824e3bc36fbe8e400f77c224b1a939b639a","kind":"commit","published_at":"2022-04-30T06:16:43.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.2.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.2.0/manifests"},{"name":"v0.1.0","sha":"d3d463f65fb4b2c4ceb7e8446855e9b47dcd959f","kind":"commit","published_at":"2022-04-29T22:14:54.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.1.0","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.1.0/manifests"},{"name":"v0.0.1-pre.3","sha":"0fc52e3345e758db6119577fca05a75fa79f44c6","kind":"commit","published_at":"2022-04-28T22:46:28.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.0.1-pre.3","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.0.1-pre.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.0.1-pre.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.3/manifests"},{"name":"v0.0.1-pre.1","sha":"7fb389549650eb0c52b090db6393bd44f60a3583","kind":"commit","published_at":"2022-01-18T19:36:39.000Z","download_url":"https://codeload.github.com/sigstore/sigstore-python/tar.gz/v0.0.1-pre.1","html_url":"https://github.com/sigstore/sigstore-python/releases/tag/v0.0.1-pre.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/sigstore/sigstore-python@v0.0.1-pre.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/tags/v0.0.1-pre.1/manifests"}]},"repo_metadata_updated_at":"2026-05-31T14:06:23.376Z","dependent_packages_count":3,"downloads":721029,"downloads_period":"last-month","dependent_repos_count":9,"rankings":{"downloads":4.448464643751531,"dependent_repos_count":4.956183038226079,"dependent_packages_count":3.2732248313335557,"stargazers_count":5.207936316725943,"forks_count":6.278259770723174,"docker_downloads_count":null,"average":4.832813720152057},"purl":"pkg:pypi/sigstore","advisories":[{"uuid":"GSA_kwCzR0hTQS1obThmLTc1eHgtdzJ2cs4ABRle","url":"https://github.com/advisories/GHSA-hm8f-75xx-w2vr","title":"sigstore CSRF possibility in OIDC authentication during signing","description":"### Summary\n\nThe sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery.\n\n### Details\n\n`_OAuthSession` creates a unique \"state\" and sends it as a parameter in the authentication request but the \"state\" in the server response seems not not be cross-checked with this value. \n\nFix should be fairly trivial.\n\n### Impact\n\nThis should be low impact: A man-in-the middle attacker could trick a sigstore-python user into signing something with an identity controlled by the attacker (by returning the response to an authentication request they created). This would be quite confusing but not dangerous.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-01-26T21:34:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N","references":["https://github.com/sigstore/sigstore-python/security/advisories/GHSA-hm8f-75xx-w2vr","https://github.com/sigstore/sigstore-python/commit/5e77497fe8f0b202bdd118949074ec2f20da69aa","https://github.com/sigstore/sigstore-python/releases/tag/v4.2.0","https://nvd.nist.gov/vuln/detail/CVE-2026-24408","https://github.com/advisories/GHSA-hm8f-75xx-w2vr"],"source_kind":"github","identifiers":["GHSA-hm8f-75xx-w2vr","CVE-2026-24408"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-26T22:00:09.441Z","updated_at":"2026-05-30T19:02:11.139Z","epss_percentage":0.00007,"epss_percentile":0.00534,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obThmLTc1eHgtdzJ2cs4ABRle","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1obThmLTc1eHgtdzJ2cs4ABRle","packages":[{"ecosystem":"pypi","package_name":"sigstore","versions":[{"first_patched_version":"4.2.0","vulnerable_version_range":"\u003c 4.2.0"}],"purl":"pkg:pypi/sigstore"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obThmLTc1eHgtdzJ2cs4ABRle/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oaGZnLWZ3cnctODd3N84ABCSW","url":"https://github.com/advisories/GHSA-hhfg-fwrw-87w7","title":"sigstore has insufficient validation of integration timestamp during verification","description":"### Summary\n\nVersions of sigstore-python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of the \"integration time\" present in \"v2\" and \"v3\" bundles during the verification flow: the \"integration time\" is verified *if* a source of signed time (such as an inclusion promise) is present, but is otherwise trusted if no source of signed time is present.\n\nThis does not affect \"v1\" bundles, as the \"v1\" bundle format always requires an inclusion promise.\n\n### Details\n\nSigstore uses signed time to support verification of signatures made against short-lived signing keys. \n\n### Impact\n\nThe impact and severity of this weakness is *low*, as Sigstore contains multiple other enforcing components that prevent an attacker who modifies the integration timestamp within a bundle from impersonating a valid signature. In particular, an attacker who modifies the integration timestamp can induce a Denial of Service, but in no different manner than already possible with bundle access (e.g. modifying the signature itself such that it fails to verify).\n\nSeparately, an attacker could upload a *new* entry to the transparency service, and substitute their new entry's time. However, this would still be rejected at validation time, as the new entry's (valid) signed time would be outside the validity window of the original signing certificate and would nonetheless render the attacker auditable.\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-12-11T18:42:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","references":["https://github.com/sigstore/sigstore-python/security/advisories/GHSA-hhfg-fwrw-87w7","https://nvd.nist.gov/vuln/detail/CVE-2024-55655","https://github.com/sigstore/sigstore-python/commit/300b502ae99ebfaace124f1f4e422a6a669369cf","https://github.com/sigstore/sigstore-python/releases/tag/v3.6.0","https://github.com/advisories/GHSA-hhfg-fwrw-87w7"],"source_kind":"github","identifiers":["GHSA-hhfg-fwrw-87w7","CVE-2024-55655"],"repository_url":"https://github.com/sigstore/sigstore-python","blast_radius":2.5764547754861775,"created_at":"2024-12-11T19:08:07.634Z","updated_at":"2026-05-31T19:04:17.538Z","epss_percentage":0.00096,"epss_percentile":0.26518,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oaGZnLWZ3cnctODd3N84ABCSW","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oaGZnLWZ3cnctODd3N84ABCSW","packages":[{"ecosystem":"pypi","package_name":"sigstore","versions":[{"first_patched_version":"3.6.0","vulnerable_version_range":"\u003e= 2.0.0, \u003c 3.6.0"}],"purl":"pkg:pypi/sigstore"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oaGZnLWZ3cnctODd3N84ABCSW/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/pypi/sigstore","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/pypi/sigstore","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/pypi/sigstore/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-04-22T20:05:45.656Z","issues_count":363,"pull_requests_count":1615,"avg_time_to_close_issue":4443610.637931035,"avg_time_to_close_pull_request":306445.4505640345,"issues_closed_count":290,"pull_requests_closed_count":1507,"pull_request_authors_count":40,"issue_authors_count":53,"avg_comments_per_issue":2.6556473829201104,"avg_comments_per_pull_request":1.484829721362229,"merged_pull_requests_count":1357,"bot_issues_count":75,"bot_pull_requests_count":937,"past_year_issues_count":67,"past_year_pull_requests_count":222,"past_year_avg_time_to_close_issue":744797.3636363636,"past_year_avg_time_to_close_pull_request":177443.73410404625,"past_year_issues_closed_count":33,"past_year_pull_requests_closed_count":173,"past_year_pull_request_authors_count":7,"past_year_issue_authors_count":11,"past_year_avg_comments_per_issue":1.373134328358209,"past_year_avg_comments_per_pull_request":1.3153153153153152,"past_year_bot_issues_count":6,"past_year_bot_pull_requests_count":127,"past_year_merged_pull_requests_count":157,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/issues","maintainers":[{"login":"woodruffw","count":401,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/woodruffw"},{"login":"jku","count":134,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jku"},{"login":"tetsuo-cpp","count":84,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tetsuo-cpp"},{"login":"di","count":65,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/di"},{"login":"tnytown","count":21,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tnytown"},{"login":"jleightcap","count":13,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jleightcap"},{"login":"DarkaMaul","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/DarkaMaul"},{"login":"bobcallaway","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bobcallaway"},{"login":"lukehinds","count":3,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lukehinds"},{"login":"mbestavros","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mbestavros"},{"login":"segiddins","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/segiddins"},{"login":"facutuesca","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/facutuesca"},{"login":"loosebazooka","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/loosebazooka"}],"active_maintainers":[{"login":"jku","count":79,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jku"},{"login":"woodruffw","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/woodruffw"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/sigstore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/sigstore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/sigstore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/sigstore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/sigstore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/sigstore/codemeta","maintainers":[{"uuid":"di","login":"di","name":null,"email":null,"url":null,"packages_count":52,"html_url":"https://pypi.org/user/di/","role":null,"created_at":"2022-11-23T22:47:02.609Z","updated_at":"2022-11-23T22:47:02.609Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/di/packages"},{"uuid":"woodruffw","login":"woodruffw","name":null,"email":null,"url":null,"packages_count":29,"html_url":"https://pypi.org/user/woodruffw/","role":null,"created_at":"2022-11-23T22:47:02.622Z","updated_at":"2022-11-23T22:47:02.622Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/woodruffw/packages"}],"registry":{"name":"pypi.org","url":"https://pypi.org","ecosystem":"pypi","default":true,"packages_count":875243,"maintainers_count":374374,"namespaces_count":0,"keywords_count":285845,"github":"pypi","metadata":{"funded_packages_count":54057},"icon_url":"https://github.com/pypi.png","created_at":"2022-04-04T15:19:23.364Z","updated_at":"2026-05-29T05:11:24.287Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/namespaces"}}],"commits":{"id":1254697,"full_name":"sigstore/sigstore-python","default_branch":"main","total_commits":1212,"total_committers":39,"total_bot_commits":667,"total_bot_committers":2,"mean_commits":31.076923076923077,"dds":0.4653465346534653,"past_year_total_commits":255,"past_year_total_committers":13,"past_year_total_bot_commits":180,"past_year_total_bot_committers":2,"past_year_mean_commits":19.615384615384617,"past_year_dds":0.3176470588235294,"last_synced_at":"2026-03-27T02:23:35.189Z","last_synced_commit":"78172da945f32dcda430514e38cc637d33342fdd","created_at":"2023-03-29T14:31:16.366Z","updated_at":"2026-03-27T02:23:25.012Z","committers":[{"name":"dependabot[bot]","email":"49699333+dependabot[bot]","login":"dependabot[bot]","count":648},{"name":"William Woodruff","email":"william@trailofbits.com","login":"woodruffw","count":250},{"name":"Jussi Kukkonen","email":"jkukkonen@google.com","login":"jku","count":66},{"name":"Alex Cameron","email":"asc@tetsuo.sh","login":"tetsuo-cpp","count":64},{"name":"Dustin Ingram","email":"di","login":"di","count":48},{"name":"Andrew Pan","email":"3821575+tnytown","login":"tnytown","count":20},{"name":"github-actions[bot]","email":"41898282+github-actions[bot]","login":"github-actions[bot]","count":19},{"name":"Facundo Tuesca","email":"facundo.tuesca@trailofbits.com","login":"facutuesca","count":15},{"name":"Ramon Petgrave","email":"32398091+ramonpetgrave64","login":"ramonpetgrave64","count":11},{"name":"Jack Leightcap","email":"jack.leightcap@trailofbits.com","login":"jleightcap","count":10},{"name":"dm","email":"alexis.challande@trailofbits.com","login":"DarkaMaul","count":7},{"name":"Dimitri Papadopoulos Orfanos","email":"3234522+DimitriPapadopoulos","login":"DimitriPapadopoulos","count":5},{"name":"Aleks","email":"121458075+SequeI","login":"SequeI","count":4},{"name":"Bob Callaway","email":"bobcallaway","login":"bobcallaway","count":4},{"name":"Javan Lacerda","email":"javanlacerda@google.com","login":"javanlacerda","count":4},{"name":"Maya Costantini","email":"66788861+mayaCostantini","login":"mayaCostantini","count":4},{"name":"Hugo van Kemenade","email":"1324225+hugovk","login":"hugovk","count":3},{"name":"Luke Hinds","email":"7058938+lukehinds","login":"lukehinds","count":2},{"name":"Diogo Teles Sant'Anna","email":"diogoteles08@gmail.com","login":"diogoteles08","count":2},{"name":"Colleen Murphy","email":"cmurphy","login":"cmurphy","count":2},{"name":"Christian S. Perone","email":"perone","login":"perone","count":2},{"name":"Azeem Shaikh","email":"azeemshaikh38@gmail.com","login":"azeemshaikh38","count":2},{"name":"asraa","email":"asraa@google.com","login":"asraa","count":2},{"name":"laurentsimon","email":"64505099+laurentsimon","login":"laurentsimon","count":2},{"name":"Hayden B","email":"hblauzvern@gmail.com","login":"haydentherapper","count":2},{"name":"Cyril Cordoui","email":"ccordoui@redhat.com","login":null,"count":1},{"name":"Aaron Lew","email":"64337293+aaronlew02","login":"aaronlew02","count":1},{"name":"Cameron","email":"561860+wallies","login":"wallies","count":1},{"name":"Copilot","email":"198982749+Copilot","login":"Copilot","count":1},{"name":"David A. Wheeler","email":"dwheeler@dwheeler.com","login":"david-a-wheeler","count":1},{"name":"Emile","email":"48302236+emilejbm","login":"emilejbm","count":1},{"name":"Kurt McKee","email":"contactme@kurtmckee.org","login":"kurtmckee","count":1},{"name":"Rob Ankeny","email":"ankenyr@gmail.com","login":"ankenyr","count":1},{"name":"Sachin Sampras M","email":"sampras343@gmail.com","login":"sampras343","count":1},{"name":"Samuel Giddins","email":"segiddins@segiddins.me","login":"segiddins","count":1},{"name":"Seth Michael Larson","email":"sethmichaellarson@gmail.com","login":"sethmlarson","count":1},{"name":"StepSecurity Bot","email":"bot@stepsecurity.io","login":"step-security-bot","count":1},{"name":"Tzu-ping Chung","email":"uranusjr@gmail.com","login":"uranusjr","count":1},{"name":"Андрій Шовкошитний","email":"198119344+enlightened88","login":"enlightened88","count":1}],"past_year_committers":[{"name":"dependabot[bot]","email":"49699333+dependabot[bot]","login":"dependabot[bot]","count":174},{"name":"Jussi Kukkonen","email":"jkukkonen@google.com","login":"jku","count":45},{"name":"Ramon Petgrave","email":"32398091+ramonpetgrave64","login":"ramonpetgrave64","count":11},{"name":"github-actions[bot]","email":"41898282+github-actions[bot]","login":"github-actions[bot]","count":6},{"name":"William Woodruff","email":"william@trailofbits.com","login":"woodruffw","count":6},{"name":"Aleks","email":"121458075+SequeI","login":"SequeI","count":4},{"name":"Hugo van Kemenade","email":"1324225+hugovk","login":"hugovk","count":2},{"name":"Colleen Murphy","email":"cmurphy","login":"cmurphy","count":2},{"name":"Андрій Шовкошитний","email":"198119344+enlightened88","login":"enlightened88","count":1},{"name":"Sachin Sampras M","email":"sampras343@gmail.com","login":"sampras343","count":1},{"name":"Dustin Ingram","email":"di","login":"di","count":1},{"name":"Copilot","email":"198982749+Copilot","login":"Copilot","count":1},{"name":"Aaron Lew","email":"64337293+aaronlew02","login":"aaronlew02","count":1}],"commits_url":"https://commits.ecosyste.ms/api/v1/hosts/GitHub/repositories/sigstore%2Fsigstore-python/commits","host":{"name":"GitHub","url":"https://github.com","kind":"github","last_synced_at":"2026-03-29T00:04:24.059Z","repositories_count":6205199,"commits_count":927989477,"contributors_count":35820033,"owners_count":1144025,"icon_url":"https://github.com/github.png","host_url":"https://commits.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://commits.ecosyste.ms/api/v1/hosts/GitHub/repositories"}},"issues":{"table":{}},"events":null,"keywords":["codesigning","python","security","supply-chain"],"dependencies":[{"ecosystem":"actions","filepath":".github/actions/upload-coverage/action.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.200Z","updated_at":"2023-02-17T10:15:49.200Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/actions/upload-coverage/action.yml","dependencies":[{"id":7738462308,"package_name":"actions/upload-artifact","ecosystem":"actions","requirements":"v3.1.0","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/ci.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.229Z","updated_at":"2023-02-17T10:15:49.229Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/ci.yml","dependencies":[{"id":7738462324,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462325,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"d27e3f3d7c64b4bbf8e4abfb9b63b83e846e0435","direct":true,"kind":"composite","optional":false},{"id":7738462326,"package_name":"./.github/actions/upload-coverage","ecosystem":"actions","requirements":"*","direct":true,"kind":"composite","optional":false},{"id":7738462327,"package_name":"re-actors/alls-green","ecosystem":"actions","requirements":"05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe","direct":true,"kind":"composite","optional":false},{"id":7738462328,"package_name":"actions/checkout","ecosystem":"actions","requirements":"755da8c3cf115ac066823e79a1e1788f8940201b","direct":true,"kind":"composite","optional":false},{"id":7738462329,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"5ccb29d8773c3f3f653e1705f474dfaa8a06a912","direct":true,"kind":"composite","optional":false},{"id":7738462330,"package_name":"actions/download-artifact","ecosystem":"actions","requirements":"v3.0.2","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/conformance.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.283Z","updated_at":"2023-02-17T10:15:49.283Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/conformance.yml","dependencies":[{"id":7738462357,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462358,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"d27e3f3d7c64b4bbf8e4abfb9b63b83e846e0435","direct":true,"kind":"composite","optional":false},{"id":7738462359,"package_name":"sigstore/sigstore-conformance","ecosystem":"actions","requirements":"0748d63c53810e36cc3f4bbe4114301080f0d844","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/docs.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.345Z","updated_at":"2023-02-17T10:15:49.345Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/docs.yml","dependencies":[{"id":7738462401,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462402,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"d27e3f3d7c64b4bbf8e4abfb9b63b83e846e0435","direct":true,"kind":"composite","optional":false},{"id":7738462403,"package_name":"actions/upload-pages-artifact","ecosystem":"actions","requirements":"253fd476ed429e83b7aae64a92a75b4ceb1a17cf","direct":true,"kind":"composite","optional":false},{"id":7738462404,"package_name":"actions/deploy-pages","ecosystem":"actions","requirements":"0243b6c10d06cb8e95ed8ee471231877621202c0","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/lint.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.373Z","updated_at":"2023-02-17T10:15:49.373Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/lint.yml","dependencies":[{"id":7738462423,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462424,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"d27e3f3d7c64b4bbf8e4abfb9b63b83e846e0435","direct":true,"kind":"composite","optional":false},{"id":7738462425,"package_name":"re-actors/alls-green","ecosystem":"actions","requirements":"05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/release.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.426Z","updated_at":"2023-02-17T10:15:49.426Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/release.yml","dependencies":[{"id":7738462518,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462519,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"d27e3f3d7c64b4bbf8e4abfb9b63b83e846e0435","direct":true,"kind":"composite","optional":false},{"id":7738462520,"package_name":"actions/upload-artifact","ecosystem":"actions","requirements":"0b7f8abb1508181956e8e162db84b466c27e18ce","direct":true,"kind":"composite","optional":false},{"id":7738462521,"package_name":"actions/download-artifact","ecosystem":"actions","requirements":"9bc31d5ccc31df68ecc42ccf4149144866c47d8a","direct":true,"kind":"composite","optional":false},{"id":7738462522,"package_name":"pypa/gh-action-pypi-publish","ecosystem":"actions","requirements":"c7f29f7adef1a245bd91520e94867e5c6eedddcc","direct":true,"kind":"composite","optional":false},{"id":7738462523,"package_name":"softprops/action-gh-release","ecosystem":"actions","requirements":"de2c0eb89ae2a093876385947365aca7b0e5f844","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/scorecards-analysis.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.481Z","updated_at":"2023-02-17T10:15:49.481Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/scorecards-analysis.yml","dependencies":[{"id":7738462540,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462541,"package_name":"ossf/scorecard-action","ecosystem":"actions","requirements":"e38b1902ae4f44df626f11ba0734b14fb91f8f86","direct":true,"kind":"composite","optional":false},{"id":7738462542,"package_name":"actions/upload-artifact","ecosystem":"actions","requirements":"6673cd052c4cd6fcf4b4e6e60ea986c889389535","direct":true,"kind":"composite","optional":false},{"id":7738462543,"package_name":"github/codeql-action/upload-sarif","ecosystem":"actions","requirements":"17573ee1cc1b9d061760f3a006fc4aac4f944fd5","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/staging-tests.yml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:49.513Z","updated_at":"2023-02-17T10:15:49.513Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/staging-tests.yml","dependencies":[{"id":7738462565,"package_name":"actions/checkout","ecosystem":"actions","requirements":"ac593985615ec2ede58e132d2e21d2b1cbd6127c","direct":true,"kind":"composite","optional":false},{"id":7738462566,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"d27e3f3d7c64b4bbf8e4abfb9b63b83e846e0435","direct":true,"kind":"composite","optional":false},{"id":7738462567,"package_name":"peter-evans/create-issue-from-file","ecosystem":"actions","requirements":"433e51abf769039ee20ba1293a088ca19d573b7f","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"pypi","filepath":"install/requirements.in","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:50.121Z","updated_at":"2023-02-17T10:15:50.121Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/install/requirements.in","dependencies":[{"id":7738462824,"package_name":"sigstore","ecosystem":"pypi","requirements":"*","direct":true,"kind":"runtime","optional":false}]},{"ecosystem":"pypi","filepath":"install/requirements.txt","sha":null,"kind":"lockfile","created_at":"2023-02-17T10:15:50.932Z","updated_at":"2023-02-17T10:15:50.932Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/install/requirements.txt","dependencies":[{"id":7738465128,"package_name":"appdirs","ecosystem":"pypi","requirements":"==1.4.4","direct":false,"kind":"runtime","optional":false},{"id":7738465129,"package_name":"betterproto","ecosystem":"pypi","requirements":"==2.0.0b5","direct":false,"kind":"runtime","optional":false},{"id":7738465130,"package_name":"certifi","ecosystem":"pypi","requirements":"==2022.12.7","direct":false,"kind":"runtime","optional":false},{"id":7738465131,"package_name":"cffi","ecosystem":"pypi","requirements":"==1.15.1","direct":false,"kind":"runtime","optional":false},{"id":7738465132,"package_name":"charset-normalizer","ecosystem":"pypi","requirements":"==3.0.1","direct":false,"kind":"runtime","optional":false},{"id":7738465133,"package_name":"cryptography","ecosystem":"pypi","requirements":"==39.0.1","direct":false,"kind":"runtime","optional":false},{"id":7738465134,"package_name":"grpclib","ecosystem":"pypi","requirements":"==0.4.3","direct":false,"kind":"runtime","optional":false},{"id":7738465135,"package_name":"h2","ecosystem":"pypi","requirements":"==4.1.0","direct":false,"kind":"runtime","optional":false},{"id":7738465136,"package_name":"hpack","ecosystem":"pypi","requirements":"==4.0.0","direct":false,"kind":"runtime","optional":false},{"id":7738465137,"package_name":"hyperframe","ecosystem":"pypi","requirements":"==6.0.1","direct":false,"kind":"runtime","optional":false},{"id":7738465138,"package_name":"idna","ecosystem":"pypi","requirements":"==3.4","direct":false,"kind":"runtime","optional":false},{"id":7738465139,"package_name":"multidict","ecosystem":"pypi","requirements":"==6.0.4","direct":false,"kind":"runtime","optional":false},{"id":7738465140,"package_name":"pycparser","ecosystem":"pypi","requirements":"==2.21","direct":false,"kind":"runtime","optional":false},{"id":7738465141,"package_name":"pydantic","ecosystem":"pypi","requirements":"==1.10.5","direct":false,"kind":"runtime","optional":false},{"id":7738465142,"package_name":"pyjwt","ecosystem":"pypi","requirements":"==2.6.0","direct":false,"kind":"runtime","optional":false},{"id":7738465143,"package_name":"pyopenssl","ecosystem":"pypi","requirements":"==23.0.0","direct":false,"kind":"runtime","optional":false},{"id":7738465144,"package_name":"python-dateutil","ecosystem":"pypi","requirements":"==2.8.2","direct":false,"kind":"runtime","optional":false},{"id":7738465145,"package_name":"requests","ecosystem":"pypi","requirements":"==2.28.2","direct":false,"kind":"runtime","optional":false},{"id":7738465146,"package_name":"securesystemslib","ecosystem":"pypi","requirements":"==0.26.0","direct":false,"kind":"runtime","optional":false},{"id":7738465147,"package_name":"sigstore","ecosystem":"pypi","requirements":"==1.1.0","direct":false,"kind":"runtime","optional":false},{"id":7738465148,"package_name":"sigstore-protobuf-specs","ecosystem":"pypi","requirements":"==0.1.0","direct":false,"kind":"runtime","optional":false},{"id":7738465149,"package_name":"six","ecosystem":"pypi","requirements":"==1.16.0","direct":false,"kind":"runtime","optional":false},{"id":7738465150,"package_name":"tuf","ecosystem":"pypi","requirements":"==2.1.0","direct":false,"kind":"runtime","optional":false},{"id":7738465151,"package_name":"typing-extensions","ecosystem":"pypi","requirements":"==4.5.0","direct":false,"kind":"runtime","optional":false},{"id":7738465152,"package_name":"urllib3","ecosystem":"pypi","requirements":"==1.26.14","direct":false,"kind":"runtime","optional":false}]},{"ecosystem":"pypi","filepath":"pyproject.toml","sha":null,"kind":"manifest","created_at":"2023-02-17T10:15:52.726Z","updated_at":"2023-02-17T10:15:52.726Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/pyproject.toml","dependencies":[{"id":7738467739,"package_name":"appdirs","ecosystem":"pypi","requirements":"~= 1.4","direct":true,"kind":"runtime","optional":false},{"id":7738467740,"package_name":"cryptography","ecosystem":"pypi","requirements":"\u003e= 39","direct":true,"kind":"runtime","optional":false},{"id":7738467741,"package_name":"importlib_resources","ecosystem":"pypi","requirements":"~= 5.7; python_version \u003c '3.11'","direct":true,"kind":"runtime","optional":false},{"id":7738467742,"package_name":"pydantic","ecosystem":"pypi","requirements":"*","direct":true,"kind":"runtime","optional":false},{"id":7738467743,"package_name":"pyjwt","ecosystem":"pypi","requirements":"\u003e= 2.1","direct":true,"kind":"runtime","optional":false},{"id":7738467744,"package_name":"pyOpenSSL","ecosystem":"pypi","requirements":"\u003e= 23.0.0","direct":true,"kind":"runtime","optional":false},{"id":7738467842,"package_name":"requests","ecosystem":"pypi","requirements":"*","direct":true,"kind":"runtime","optional":false},{"id":7738467843,"package_name":"securesystemslib","ecosystem":"pypi","requirements":"*","direct":true,"kind":"runtime","optional":false},{"id":7738467844,"package_name":"sigstore-protobuf-specs","ecosystem":"pypi","requirements":"~= 0.1.0","direct":true,"kind":"runtime","optional":false},{"id":7738467845,"package_name":"tuf","ecosystem":"pypi","requirements":"~= 2.1","direct":true,"kind":"runtime","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/pin-requirements.yml","sha":null,"kind":"manifest","created_at":"2023-07-13T02:54:43.164Z","updated_at":"2023-07-13T02:54:43.164Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/pin-requirements.yml","dependencies":[{"id":11387921394,"package_name":"actions/checkout","ecosystem":"actions","requirements":"c85c95e3d7251135ab7dc9ce3241c5835cc595a9","direct":true,"kind":"composite","optional":false},{"id":11387921395,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"bd6b4b6205c4dbad673328db7b31b7fab9e241c0","direct":true,"kind":"composite","optional":false},{"id":11387921396,"package_name":"peter-evans/create-pull-request","ecosystem":"actions","requirements":"153407881ec5c347639a548ade7d8ad1d6740e38","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/requirements.yml","sha":null,"kind":"manifest","created_at":"2023-07-13T02:54:43.181Z","updated_at":"2023-07-13T02:54:43.181Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/requirements.yml","dependencies":[{"id":11387921397,"package_name":"actions/checkout","ecosystem":"actions","requirements":"c85c95e3d7251135ab7dc9ce3241c5835cc595a9","direct":true,"kind":"composite","optional":false},{"id":11387921398,"package_name":"actions/setup-python","ecosystem":"actions","requirements":"bd6b4b6205c4dbad673328db7b31b7fab9e241c0","direct":true,"kind":"composite","optional":false}]},{"ecosystem":"actions","filepath":".github/workflows/depsreview.yml","sha":null,"kind":"manifest","created_at":"2023-11-07T16:06:39.115Z","updated_at":"2023-11-07T16:06:39.115Z","repository_link":"https://github.com/sigstore/sigstore-python/blob/main/.github/workflows/depsreview.yml","dependencies":[]}],"score":23.089617086318643,"created_at":"2025-12-10T07:37:45.044Z","updated_at":"2026-05-31T19:30:42.157Z","avatar_url":"https://github.com/sigstore.png","language":"Python","codemeta":null,"publiccode":null,"project_url":"https://summary.ecosyste.ms/api/v1/projects/369736","html_url":"https://summary.ecosyste.ms/projects/369736"}