sigstore
v0.13.0 GrowingAn experimental crate to interact with sigstore
Quick Verdict
- !Pre-1.0: API may have breaking changes
- โTrusted by 158 crates
- !Heavy dependency tree (62 direct deps)
- โPermissive license (Apache-2.0)
Security
Deep Insights
45.3K downloads in the last 30 days (1.5K/day), up 21% from the previous period.
158 crates depend on sigstore. Reasonable ecosystem adoption, though not yet a core dependency.
Despite being 4+ years old, sigstore hasn't reached 1.0 yet. Expect potential API changes between versions.
62 direct dependencies. Consider the impact on compile times and supply chain complexity.
Notable dependents include pcu, sigstore-verification, blue-build-process-management, bpfman, bpfman-api. When high-quality crates choose sigstore, it's a strong quality signal.
Health Breakdown
Recency, release consistency, active ratio
Yanked ratio, deps, size, maturity, features
Reverse deps, ownership, ecosystem
Downloads, momentum, growth trend
Docs, repo, license, metadata
Download Trend
Top Dependents
Version Adoption
Release Timeline
Feature Flags
default =["full", "native-tls"]