lurq

npm package

Home

@sigstore/sign

The @sigstore/sign library is designed for generating Sigstore signatures, enabling secure signing of artifacts with keyless options. It is particularly useful in CI/CD environments where OIDC credentials can be detected automatically. This library provides the necessary components to create custom signing workflows and manage signatures effectively.

lurq health score
81/100
Confidence
proven
Weekly downloads
11,239,151
Latest version
5.0.0
Last release
Aug 4, 2026
License
Apache-2.0

Should you depend on @sigstore/sign?

lurq's verdict: low

  • No known advisories

Check this from your coding agent

This page is a daily snapshot. lurq's verify tool checks @sigstore/sign at the exact version your agent is about to install, and compat checks it against the rest of your stack. One command connects Claude Code, Cursor, VS Code and other agents:

npx lurqrun

Free to start. Quickstart

Other styling packages lurq scores

Scored from public signals (npm registry, GitHub, deps.dev and advisory databases). Data as of Sep 4, 2026; this page refreshes every 24 hours. Source repository.