Sigstore Software Supply Chain Security
Unified software supply chain security workflow combining Sigstore's Rekor transparency log and Fulcio certificate authority. Enables artifact signing, verification, certificate issuance, and transparency log auditing for DevOps engineers, security teams, and platform administrators building secure software delivery pipelines.
What You Can Do
MCP Tools
rekor-create-log-entry
Submit a signed artifact to the Rekor transparency log to create an immutable audit record
rekor-get-log-entry
Retrieve a specific Rekor transparency log entry by UUID, including the inclusion proof
rekor-search-artifact
Search the Rekor index to find log entries for a specific artifact hash or signer email
rekor-search-entries
Retrieve multiple Rekor log entries by UUIDs or log indexes
rekor-get-log-info
Get current Rekor transparency log tree size and signed tree head information
fulcio-create-signing-certificate
Request a short-lived X.509 signing certificate from Fulcio using OIDC identity token
fulcio-get-trust-bundle
Retrieve the Fulcio CA root and intermediate certificates for offline verification
fulcio-get-configuration
Get the Fulcio CA configuration including all supported OIDC identity providers