npm package
Home@sigstore/sign
The @sigstore/sign library is designed for generating Sigstore signatures, enabling secure signing of artifacts with keyless options. It is particularly useful in CI/CD environments where OIDC credentials can be detected automatically. This library provides the necessary components to create custom signing workflows and manage signatures effectively.
- lurq health score
- 81/100
- Confidence
- proven
- Weekly downloads
- 11,239,151
- Latest version
- 5.0.0
- Last release
- Aug 4, 2026
- License
- Apache-2.0
Should you depend on @sigstore/sign?
lurq's verdict: low
- No known advisories
Check this from your coding agent
This page is a daily snapshot. lurq's verify tool checks @sigstore/sign at the exact version your agent is about to install, and compat checks it against the rest of your stack. One command connects Claude Code, Cursor, VS Code and other agents:
npx lurqrun
Free to start. Quickstart
Other styling packages lurq scores
- @mui/private-theming94/100 · proven
- @mui/system93/100 · proven
- remeda93/100 · proven
- gaxios91/100 · proven
- @internationalized/number91/100 · proven
Scored from public signals (npm registry, GitHub, deps.dev and advisory databases). Data as of Sep 4, 2026; this page refreshes every 24 hours. Source repository.