Cosign

Windows · Mac · Linux · Self-hosted

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

Cosign signs and verifies OCI container images and other software artifacts. It can store container signatures alongside images in an OCI registry and publish generic artifacts through OCI. Supported targets include blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, eBPF modules, and in-toto attestations signed with DSSE. The default keyless method uses temporary keys held in memory, short-lived Fulcio certificates, and entries in the Rekor transparency log. Other signing options include hardware and KMS keys, encrypted keypairs generated by Cosign, and user-provided PKI. The project lists integrations with AWS ECR, Google Artifact Registry, Docker Hub, Azure Container Registry, GitLab Container Registry, and GitHub Container Registry, and provides CI guidance for GitHub Actions and GitLab. Offline verification works when the image and signature materials are available locally and a trusted root is supplied. Cosign is free and available for Linux, macOS, Windows, and self-hosted use. It is described as a legacy signing system, and its CLI-focused design has no API stability guarantees.

Who it is for

Cosign suits teams signing and verifying software artifacts, including open-source package managers and CI/CD workflows. It is less suited to application integrations, which its documentation does not recommend.

What is good

  • Signs and verifies OCI containers and many other artifact types.
  • Supports keyless, hardware, KMS, and user-provided PKI signing.
  • Can verify offline with local materials and a trusted root.
  • Provides CI guidance for GitHub Actions and GitLab.

What to know first

  • Documentation describes Cosign as a legacy signing system.
  • No API stability guarantees; application integration is not recommended.
  • Key generation is limited to ECDSA-P256, with SHA256 hashes for specified signing methods.
  • Keyless signing may publish identity information in public logs.

Freedom251 review

Cosign: the full review

Cosign offers several signing approaches and supports a broad range of artifact workflows, including offline verification when the required materials are local. Its legacy status and lack of API stability guarantees matter for teams considering it as an application integration.

Overview

Cosign is a free command-line tool for signing and verifying OCI container images and other software artifacts. It is best suited to open-source package managers and teams running signing workflows from a CLI or CI pipeline. Its range of signing methods is a strong fit for artifact workflows, but its legacy status and lack of API stability make it a poor choice for new application integrations.

Key features

Cosign’s default keyless flow uses ephemeral keys held in memory, short-lived certificates from Sigstore’s public-good Fulcio certificate authority, and entries in Rekor’s transparency log. That avoids managing a persistent key for this workflow, but signing may publish identity details such as an account email in a public log, where they cannot later be removed. Teams should weigh that exposure before choosing keyless signing.

For different custody requirements, Cosign supports hardware and KMS signing, encrypted keypairs it generates, and bring-your-own PKI. It generates only ECDSA-P256 keys and uses SHA256 hashes for ephemeral keyless and managed-key signing, so workflows requiring other algorithms or hashes should look elsewhere.

Container signatures can be stored alongside images in an OCI registry. Cosign also provides utilities to publish generic artifacts through OCI and supports in-toto attestations with DSSE-signed payloads. Its supported targets include images, blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, and eBPF modules. This breadth suits supply-chain workflows that need to cover more than container images.

The project identifies tested registries including AWS ECR, Google Artifact Registry, Docker Hub, Azure Container Registry, GitLab Container Registry, and GitHub Container Registry. Installation guidance covers GitHub Actions and GitLab CI/CD, as well as Linux and macOS binaries, Go, Homebrew, Arch, Alpine, Nix, and container images. Cosign can also verify signatures offline when the image and signature materials are local and a trusted root is supplied, a useful option for disconnected environments with those prerequisites in place.

The project recommends verifying downloaded binaries; releases are signed using keyless signing and an artifact key. For support, users can open a GitHub issue or ask in the Sigstore Slack channel. Vulnerability reports go to [email protected], and Sigstore says its Security Response Committee will acknowledge them within 24 hours.

Pricing

Cosign is open-source software with a free plan at 0.00 USD per free, billed Free. There is no free trial because the software is free. The plan includes a certificate, HSM key protection, trusted timestamping, and CI/CD signing, and supports the artifact targets described above. No hosted service or usage limits are stated; this is a software tool rather than a hosted signing service.

Platforms

Cosign supports Linux, macOS, Windows, and self-hosted use. Installation guidance spans release binaries, package managers, Go, CI pipelines, and container images, giving teams several ways to put the CLI into their existing environments.

Who it's for

Cosign is most compelling for open-source package managers and teams that need to sign or verify artifacts through a CLI or CI workflow, particularly when they need multiple key-custody options, OCI registry storage, attestations, or offline verification. It is not recommended for application integration: its functions were designed for the CLI, and the project provides no API stability guarantees. Sigstore-go is recommended instead for verification integrations.

Pros and cons

  • Pro: Multiple signing approaches, including keyless, hardware, KMS, generated encrypted keypairs, and bring-your-own PKI, accommodate different custody needs.
  • Pro: OCI storage, generic artifact publishing, attestations, and a broad set of supported targets cover workflows beyond container images.
  • Pro: Offline verification is possible when local image and signature materials and a trusted root are available.
  • Con: Public transparency logging can expose identity details that cannot be removed later.
  • Con: ECDSA-P256 key generation and SHA256 use for ephemeral keyless and managed-key signing constrain workflows that require other algorithms or hashes.
  • Con: Its legacy status and lack of API stability guarantees make it a poor foundation for application integrations.

Alternatives

For a wider code signing software comparison, consider what kind of workflow and service model you need. SignPath is another free option, with an open-source plan at 0.00 USD per free subject to eligibility conditions. SignServer may suit teams wanting basic code, document, or container signing and timestamping, with a free community plan and a free trial. Sigstore is a free alternative for developers and software providers, with API support among its platforms.

SignPath Foundation offers a free subscription for eligible, actively maintained open-source projects released under an OSI-approved license. For a paid option with custom pricing, DigiCert Software Trust Manager spans API, web, and desktop platforms. Bamboo Deploy has a Premium plan at 15.00 USD per month, billed $45 every 3 months, for up to 50 apps and 1GB cloud hosting. Red Hat Trusted Artifact Signer and ComSignTrust Secure Code Signing Platform (ASCS) are paid alternatives with custom pricing.

Verdict

Choose Cosign if you need a free, flexible CLI for signing and verifying software artifacts across OCI registries and CI workflows, especially for open-source package management. Its breadth of key options and artifact support is the main reason to choose it. Look elsewhere if you need stable APIs for an application integration, other signing algorithms or hashes, or a keyless flow that does not publish identity information to a public log.

Cosign plans and pricing

All plans
Cosign Free Free; open-source software No hosted service or usage limits stated github.com · 3 Oct 2026

Compared on code signing software

Free plan
Yes
Supported targets
OCI container images, blobs, binaries, scripts, configuration files, SBOMs, WASM modules, Tekton bundles, eBPF modules, and In-Toto attestations
Certificate provided
Yes
Cloud signing
No
HSM key protection
Yes
Trusted timestamping
Yes
CI/CD signing
Yes

Best Cosign alternatives

See all 20