cosign

sigstore·Sigstore.Cosign

Code signing and transparency for containers and binaries

winget install --id Sigstore.Cosign --exact --source winget

Latest 3.1.2·July 17, 2026

Release Notes

This may be the last Cosign v3.1 release, as we finish deprecations and removing unused functionality. Soon we'll start work on Cosign v4 where we will remove things that are currently deprecated. We'll continue to support Cosign v3, with it's opt-in backwards compatibility, as described in our versioning policy. If you haven't already, now is an excellent time to move to the bundle format that has been supported since Cosign v2.6. We have received a ton of fixes over the past month from folks using Cosign in a variety of environments - thank you all! Deprecations

  • 816f2b6 Deprecate --payload for sign and verify commands (#4991) Features
  • 5121398 docs: add OVHcloud KMS in available external plugins (#4962)
  • 38f73bb Add insecure registry flag to ko publish in kind-verify-attestation workflow (#4970)
  • 2e0749a Deprecate --output-attestation (#4958)
  • 2233166 Add bundle inspect command (#4842) Fixes
  • eb3bb86 Guard against empty certificate PEM in mutate.Signature (#4998)
  • 089731c fix(download): Validate predicate type for new bundle format
  • d996ce1 Skip nil subject entries in IntotoSubjectClaimVerifier (#5016)
  • 8ca5b20 Fix Makefile: fall back to "unknown" version info when built outside a git repo (#5000)
  • df78bf6 fix(verify): skip identity validation for security keys (#5012)
  • aebdc3a fix: include artifactType in OCI 1.1 signature referrer manifest
  • c0edaac Allow attestation download to handle both bundle types (#4996)
  • a8642c7 Fix panic in dockerfile verify on malformed FROM lines (#4979)
  • ef3e3b4 fix(release): restore signing-step auth and fail on image signing errors (#4978)
  • 16ddbcf feat(signing-config): add --base-config flag to override services from base config (#4977)
  • f17f812 fix: pass NewBundleFormat to KeyOpts in sign command (#4981)
  • 6ef8d9d fix: ignore build stage references in dockerfile verify (#4961)
  • 8dbdef5 fix: allow '=' in annotation values (#4957) Cleanup
  • 193d215 Remove unused policy evaluation code (#4936)
  • 0fc9811 Remove unused signing code (#4918)
  • 95dceda Remove unused OCI code (#4935)
  • b1dd2e9 Remove unused ephemeral signer (#4938) Documentation
  • 8184126 feat: improve verify flag shell completions (#4965)
  • ed0efe8 docs: fix Short style and add Example fields to piv-tool subcommands (#4942)
  • d41b86c docs: add Example fields to env and bundle create commands (#4941)
  • 8a7174a docs: fix Short style and add Example fields to pkcs11-tool subcommands Thanks to all contributors!

Installer type: portable

x64FE4D621D7AE5E900EE62089837C00F996AE9ACB82027D573D1D157B6EE875CB2

Details

Homepage
https://github.com/sigstore/cosign
License
Apache-2.0
Publisher
sigstore
Support
https://github.com/sigstore/cosign/issues
Moniker
cosign

Older versions (18)

3.1.1
x649D2C026E667BFD979FA7BA1CAB8C4B24D2E73F336EC2D57F7FC72C7E73E5B4B6
3.0.6
x649B85A88EBFF2D9DD30FF4984A6F61F2CEDC232DD87D81FA7F2FF3C0ED96C241C
3.0.5
x6444E9E44202B67DDFAAF5EA1234F5A265417960C4AE98C5B57C35BC40BA9DD714
3.0.4
x64A3A0DC4E8C745F9BD855EC18DB346538B78AB2C4D6D510AE4186BB4A03F35438
3.0.3
x642593655025B52B5B1C99E43464459B645A3ACBE5D4A5A9F3A766E77BEEC5A441
3.0.2
x647A137280D8686665CEB4D8565DF2A0AC63F28031E014CDCAE5D56891A6C8A400
3.0.1
x6421843DBB2E910097531CA23E9F87D0CA2AE9A412E056009EAE670B090418E8ED
2.6.1
x64049026DAE3246D6EA8201512EC3EFCE3AAB0C7F1D338D52E26C525DD02B418A0
2.6.0
x647BEB4DD1E19A72C328BBF7C0D7342D744EDBF5CBB082F227B2B76E04A21C16EF
2.5.3
x64545D87E096CAB55E213F25B6EC5C9A74C958F72D05182CEE1CD53A4EB6C2E561
2.5.2
x64FEF1C4731DA9112D4CF2F6D93AE2A1551C73116A4F73FAB7B0C15B38E95FF688
2.5.1
x647A2B09ADD2620AD618A224B7F4BD6ADFA8BAEFA7526047C1FC0EC6C313D69CD6
2.5.0
x642345667CBCF60767C1A6F678755CBB7465367761084E9D2CBB59AE0CC1A94437
2.4.3
x64A2AC24E197111C9430CB2A98F10A641164381AFB83DF036504868E4EA5720800
2.4.2
x64996E6B5E0CA712C3A2C0E182AEE957B85DF1EBA69BABAAE8A6349C0BCE0088DB
2.4.1
x648D57F8A42A981D27290C4227271FA9F0F62CA6630EB4A21D316BD6B01405B87C
2.4.0
x6488F1ADDBAE6BDD83EC2C067470C1F56B6D0D3BA35F49AD34603F2502CB2933F3
2.3.0
x647E91FD101DF73601B93061BC39DE734CDCAA26345D3BD8F925E0B53166DC0220