NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3195 most downloaded on npm
Verification of Sigstore signatures
Last release 2 months ago
04 Aug 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 16 of 16 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
16 releases · first in 2024
e66d99f: harden pre-signature checkpoint parsing
adbe253: Deduplicate transparency-log entries before counting them toward tlogThreshold, so repeated copies of a single entry no longer over-count. Th
tlogThreshold, so repeated copies of a single entry no longer over-count. This matches the existing duplicate checks for timestamps and SCTs in the same verifier.promise-retry library for @gar/promise-retrymake-fetch-happen from 15.0.3 to 15.0.4One column per month.
754e2a3: Support verification of DSSE bundles with a Rekor v2 hashedrekord transparency log entry, where the entry's digest is computed over the DSSE
hashedrekord transparency log entry, where the entry's digest is computed over the DSSE pre-authentication encoding (PAE) rather than the envelope payload46c00b3: Drop support for Node 20
7845532: Verification of OID certificate extensions
74cc6c5: Bump @sigstore/protobuf-specs from 0.3.2 to 0.4.0
383e200: Drop support for node 18
tuf-js from 2.2.1 to 3.0.0DSSEBundleBuilder to generating v0.3 bundlesRekorWitness to generating "dsse" entries instead of "intoto"toDSSEBundle and toMessageSignatureBundle generate v0.3 bundles by default620c30c: Fix to use verified timestamp when selecting which certificate authority chains should be used from the trusted root to verify Fulcio-issued
bundleFromJSON to perform full bundle validation70cb986: Generate v0.2 Sigstore bundles
f89faed: Drop support for node 16
hash function in core packagetuf-js to v2.0.0make-fetch-happen from 11.0.0 to 13.0.0cf0c3ef: Bump @sigstore/protobuf-specs from 0.3.1 to 0.3.2
c38961d: Support for verifying bundles with new v0.3 media type
redirectURL config option when signing with an OAuth identity provider46caed8: Fix bug related to loading RSA keys from the trusted key material
46caed8: Update createPublicKey to support both "spki" and "pkcs1" key types
createPublicKey to support both "spki" and "pkcs1" key types@sigstore/bundle package.tufMirrorURL and tufRootPath options to the verify function### Major Changes - 90cadd3: Promoting to 1.0.0 ### Minor Changes - 16de8c7: add DSSE type
MessageBundleBuilder class to MessageSignatureBundleBuilder@sigstore/bundle package.SerializedTLogEntry typeenvelopeToJSON/envelopeFromJSON functions for serialization/deserialization of DSSE envelopesThe 1.0.0 release 🎉
### Minor Changes - 002a7a0: Initial release
VerificationPolicy typesignature property on SignatureContent interfaceattest commandWorking toward the 1.0.0 release!
Before we get to the 1.0.0 release we'll have complete offline bundle verification including Fulcio certificate chain verification and integration with the Sigstore TUF root for retrieving the Fulcio root certificate and Rekor public key.
Your coding agent can read these notes before it upgrades. Set up the MCP server →