Sigstore 69,885 is the Linux Foundation project behind cosign 6,335 (github.com/sigstore/cosign (https://github.com/sigstore/cosign 6,335 ), 3.1.3, Apache-2.0). cosign signs an image's digest and stores the signature in the same registry, next to the image. It works in two modes: with a key pair you manage, or keyless, where an OIDC identity (a GitHub Actions 29 workflow, a Google account) gets a short-lived certificate from Sigstore's Fulcio CA and the signature is recorded in the public Rekor transparency log. Docker 514 Content Trust, Docker's older Notary v1 signing, is being retired in favor of Sigstore and the Notary Project's Notation. Sign BookNest's image in the private registry of Self-Hosted Registry with a key pair and no log:
export COSIGN_PASSWORD=bn-sign-2026
cosign generate-key-pair
cosign signing-config create --out no-tlog.json
IMG=localhost:33500/booknest-api
DIGEST=$(docker buildx imagetools inspect $IMG:1.3 --format '{{json .Manifest}}' \
| jq -r .digest)
cosign sign --yes --key cosign.key --signing-config no-tlog.json "$IMG@$DIGEST"
curl -s localhost:33500/v2/booknest-api/tags/list | jq -r '.tags[]'Private key written to cosign.key Public key written to cosign.pub Signing artifact... Pushing signature to: localhost:33500/booknest-api 1.3 sha256-ff7c8911a5d4400d55c18dde397d92d8095f5e3cac3ecc99f7f9a1c9f2ac1f8d
cosign signed the digest, never a tag, because a tag can move. The signature went into the registry as an extra tag named after the digest, sha256-<digest>, which is how cosign stores signatures on registries without the OCI 1.1 referrers API. The private key is encrypted with COSIGN_PASSWORD; keep it in a secret store or a KMS (--key awskms://...). In CI, keyless signing needs no key: a workflow with permissions: id-token: write runs cosign sign --yes <image>@<digest>.