NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3240 most downloaded on npm
Base library for Sigstore
Last release 3 months ago
25 Jun 2026
Release timing varies
gaps range from 9 days to 10 months
Nearly every release is documented
notes for 11 of 11 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
11 releases · first in 2023
04ea25a: ASN.1 parser hardening
46c00b3: Drop support for Node 20
One column per month.
b5aa4f1: Apply UTF-8 encoding to payload type during PAE calculation
8f736ef: Update the createPublicKey function to support base64-encoded keys
createPublicKey function to support base64-encoded keys74cc6c5: Bump @sigstore/protobuf-specs from 0.3.2 to 0.4.0
52005b2: Bump tuf-js from 2.2.1 to 3.0.0
tuf-js from 2.2.1 to 3.0.0DSSEBundleBuilder to generating v0.3 bundlesRekorWitness to generating "dsse" entries instead of "intoto"toDSSEBundle and toMessageSignatureBundle generate v0.3 bundles by defaultf89faed: Drop support for node 16
hash function in core packagetuf-js to v2.0.0make-fetch-happen from 11.0.0 to 13.0.046caed8: Update createPublicKey to support both "spki" and "pkcs1" key types
createPublicKey to support both "spki" and "pkcs1" key types@sigstore/bundle package.tufMirrorURL and tufRootPath options to the verify functionf05be96: Update Rekor verification to handle checkpoint values which do no include timestamps ( )
MessageBundleBuilder class to MessageSignatureBundleBuilder@sigstore/bundle package.SerializedTLogEntry typeenvelopeToJSON/envelopeFromJSON functions for serialization/deserialization of DSSE envelopesThe 1.0.0 release 🎉
ee3a521: Include subject and artifactType fields in artifact manifest for AWS ECR
subject and artifactType fields in artifact manifest for AWS ECRgetImageDigest functionencoding and dsse utility modulesRFC3161Timestamp.verify methodisCA value for the X509BasicConstraintsExtension defaults to false if no other value is present### Minor Changes - 002a7a0: Initial release
VerificationPolicy typesignature property on SignatureContent interfaceattest commandWorking toward the 1.0.0 release!
Before we get to the 1.0.0 release we'll have complete offline bundle verification including Fulcio certificate chain verification and integration with the Sigstore TUF root for retrieving the Fulcio root certificate and Rekor public key.
Your coding agent can read these notes before it upgrades. Set up the MCP server →