Verify a signed artifact offline against a Sigstore Rekor transparency log entry using a cosign bundle

domain: docs.sigstore.dev · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Sign the artifact with cosign sign-blob using the bundle output option and keyless (Fulcio-issued) signing so the bundle embeds the certificate, signature, and Rekor inclusion proof.
  2. Distribute the bundle file alongside the artifact instead of relying on a live Rekor lookup at verification time.
  3. Verify offline with cosign verify-blob, passing the bundle plus the expected certificate-identity and certificate-oidc-issuer values.
  4. Confirm cosign validates the embedded signed timestamp against the ephemeral certificate's validity window and validates the transparency log inclusion proof within the bundle before trusting the signature.
  5. Pin certificate-identity and certificate-oidc-issuer to exact expected values in automated verification scripts rather than wildcards, to prevent accepting signatures from an unintended identity.

Known gotchas

Related routes

Verify a Rekor transparency log inclusion proof for a signed artifact
docs.sigstore.dev · 6 steps · unrated
Verify a cosign-signed image or artifact offline using the --bundle flag and the new Sigstore bundle format
docs.sigstore.dev · 5 steps · unrated
Sign a file artifact with cosign sign-blob using keyless OIDC signing and produce a bundle for offline verification
sigstore.dev · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans