NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3104 most downloaded on npm
code-signing for npm packages
Last release 4 months ago
01 Jun 2026
Ships fairly regularly
a new release about every 4 months
Nearly every release is documented
notes for 33 of 34 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
40 releases · first in 2022
One column per quarter.
46c00b3: Drop support for Node 20
tuf-js from 4.x to 5.0.1tuf-js from 5.0.1 to 6.0.0adbe253: Deduplicate transparency-log entries before counting them toward tlogThreshold, so repeated copies of a single entry no longer over-count. Th
tlogThreshold, so repeated copies of a single entry no longer over-count. This matches the existing duplicate checks for timestamps and SCTs in the same verifier.promise-retry library for @gar/promise-retrymake-fetch-happen from 15.0.3 to 15.0.4754e2a3: Support verification of DSSE bundles with a Rekor v2 hashedrekord transparency log entry, where the entry's digest is computed over the DSSE
hashedrekord transparency log entry, where the entry's digest is computed over the DSSE pre-authentication encoding (PAE) rather than the envelope payloadverify(bundle[, payload][, options]) now returns a Signer object containing the public key and identity information from the verification.46c00b3: Drop support for Node 20
74cc6c5: Bump @sigstore/protobuf-specs from 0.3.2 to 0.4.0
383e200: Drop support for node 18
sign and attest functions so that they generate v0.3 Sigstore bundles by default. To continue generating v0.2 bundles, use the new legacyCompatibility flag.tuf-js from 2.2.1 to 3.0.0DSSEBundleBuilder to generating v0.3 bundlesRekorWitness to generating "dsse" entries instead of "intoto"toDSSEBundle and toMessageSignatureBundle generate v0.3 bundles by defaultcf0c3ef: Bump @sigstore/protobuf-specs from 0.3.1 to 0.3.2
require instead of require.resolve4c48c22: Add support for building v0.3 bundles
DSSEBundleBuilder with a new singleCertificate option which will trigger the creation of v0.3 Sigstore bundlesforceCache option for TUF client555dd8e: Bump @sigstore/protobuf-specs from 0.2.1 to 0.3.0
### Patch Changes - Updated dependencies [7d90262] - Updated dependencies [7d90262] - Updated dependencies [f05be96] - @sigstore/verify@1.0.0 - @sigst
@sigstore/core package555dd8e: Support for validating v0.3 bundles
tufForceCache flag to VerifyOptions type@sigstore/verify package@sigstore/core packageentryType option on RekorWitness constructorforce option to force re-initialization of local TUF cache74cc6c5: Bump @sigstore/protobuf-specs from 0.3.2 to 0.4.0
f89faed: Drop support for node 16
hash function in core packagesigstore object with individual functions/types@sigstore/tuf package instead)oidcIssuer, oidcClient, oidcClientSecret, and oidcRedirectURL from the options for the sign and attest functions. The OAuth identity provider that was associated with these options has been relocated to the @sigstore/cli package.signer from the options for the sign and attest functions (see the @sigstore/sign package if you require something other than Fulcio-style keyless signing)@sigstore/cli package instead)sigstore-utils object from public interfacetuf-js to v2.0.0make-fetch-happen from 11.0.0 to 13.0.075ba6cd: Integrate @sigstore/sign package
@sigstore/sign package@sigstore/bundle packagef1b8bad: Support for verifying v0.2 Sigstore bundles that contain inclusion proofs from Rekor
tlogThreshold/ctLogThreshold verification options to 0f374dd3: Include transparency log inclusion proof in Sigstore bundle
createVerifier function5ea8b63: Adds a new identityProvider config option for the sign/attest functions
identityProvider config option for the sign/attest functionsdsse entry type@sigstore/tuf package@sigstore/rekor-types packageIdentityProvider interface2f89e43: Update Fulcio client to handle responses with detached SCTs
cab068e: Propagate retry/timeout options to the Timestamp Authority client
retry/timeout options to the Timestamp Authority clientf4c677e: Generated bundle excludes Fulcio root and intermediate certificates
tsaServerURL option for requesting a timestamp from a Timestamp Authority APItuf.client function which returns a client for retrieving targets from the Sigstore TUF repository.tlogUpload option for sign and attest to control signature uploads to the transparency logretry and timeout options to control fetch behavior when errors occur99093bb: add specific errors codes for InternalErrors
InternalErrors6ba4fd1: Print the rekor search entry when running the sigstore attest command
sigstore attest commandd2d0702: Update CLI sign cmd to output a link to search.sigstore.dev
c2e3dd5: Add support for verification of certificate extension values encoded as UTF8String
tuf.getTarget function to retrieve targets from the Sigstore TUF repositoryc38961d: Support for verifying bundles with new v0.3 media type
redirectURL config option when signing with an OAuth identity provider46caed8: Fix bug related to loading RSA keys from the trusted key material
46caed8: Update createPublicKey to support both "spki" and "pkcs1" key types
createPublicKey to support both "spki" and "pkcs1" key types@sigstore/bundle package.tufMirrorURL and tufRootPath options to the verify function### Major Changes - 90cadd3: Promoting to 1.0.0 ### Minor Changes - 16de8c7: add DSSE type
MessageBundleBuilder class to MessageSignatureBundleBuilder@sigstore/bundle package.SerializedTLogEntry typeenvelopeToJSON/envelopeFromJSON functions for serialization/deserialization of DSSE envelopesThe 1.0.0 release 🎉
Preparing for the 1.0.0 release:
Preparing for the 1.0.0 release:
Support for latest Sigstore bundle format
9173d9c: Bump dependencies:
c6d6498: Bump @oclif/core from 2.15.0 to 3.0.1
f52ee51: Bump openid-client from 5.5.0 to 5.6.0
@tufjs/repo-mock dependencyfetch-on-conflict option when adding Rekor entries
initialize command to bootstrap local TUF cachepackage.jsonchore: bump tsconfig from node12 to node14
subject and artifactType fields in artifact manifest for AWS ECRgetImageDigest functionencoding and dsse utility modulesRFC3161Timestamp.verify methodisCA value for the X509BasicConstraintsExtension defaults to false if no other value is presentFixed issue w/ Rekor type definitions missing in published package
### Minor Changes - 002a7a0: Initial release
VerificationPolicy typesignature property on SignatureContent interfaceattest commandWorking toward the 1.0.0 release!
Before we get to the 1.0.0 release we'll have complete offline bundle verification including Fulcio certificate chain verification and integration with the Sigstore TUF root for retrieving the Fulcio root certificate and Rekor public key.
Support for new Sigstore bundle format
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →