Sign Git commits with gitsign for keyless Sigstore-backed commit provenance

domain: docs.sigstore.dev/signing/gitsign · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install `gitsign` from the Sigstore releases and configure Git to use it: `git config --global gpg.x509.program gitsign` and `git config --global gpg.format x509`
  2. Set `commit.gpgsign = true` in your global or repo-level Git config to auto-sign all commits
  3. When committing, gitsign opens a browser OIDC flow to obtain a short-lived Fulcio certificate; complete the OAuth login to obtain the signing certificate
  4. Verify a signed commit with `gitsign verify --certificate-identity-regexp '...' --certificate-oidc-issuer https://accounts.google.com HEAD`
  5. Push to GitHub; the commit will display a verified badge if the identity matches the GitHub account's associated email

Known gotchas

Related routes

Configure gitsign for keyless Git commit signing using Sigstore Fulcio and Rekor, and verify signed commits
docs.sigstore.dev · 6 steps · unrated
Sign a container image keylessly with cosign and Sigstore using GitHub Actions OIDC
docs.sigstore.dev/cosign/signing · 6 steps · unrated
Sign a container image keylessly with Cosign 2.x in a CI/CD pipeline
docs.sigstore.dev · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans