GHOSTby AlphaBravo
CatalogWhy GhostContactAccount
Ghost Container Registry — Secure, signed, FIPS-ready images·Built by AlphaBravo
Catalog/cosign

cosign

FIPS 140-3Developer tools

Cosign supports container signing, verification, and storage in an OCI registry. Written in Go, it aims to make signatures invisible infrastructure.

OverviewGuidesTags
Signed
SBOM
FIPS
CIS

Pull this image

About

About Cosign

Cosign is a CLI tool designed to sign and verify software artifacts, such as container images, using the Sigstore framework. It plays a key role in securing the software supply chain by enabling digital signatures that confirm the origin and integrity of released software.

For more details, see https://docs.sigstore.dev/.

Recently pushed

View all →
3.1.3-eb8c7271c9a9
0 CVEs26 MBAug 25
2.6.5-32a040cfe4b9
0 CVEs25 MBAug 25
3.1.3-3d7f7f700c32
0 CVEs26 MBAug 25
3.1.3-alpine3.23-93c1030eee6fAlpine
0 CVEs26 MBAug 25
2.6.5-alpine3.23-7653222d960dAlpine
0 CVEs25 MBAug 25

Image details

Distribution
AlpineDebian
Architecture
amd64
Latest size
26 MB
Variants
Base + FIPS
Last pushed
Aug 25, 2026
Last scanned
Aug 25, 2026 · Trivy

Resources

Documentation ↗
Available tags
23 tags
View tags →
Latest digest
sha256:fe9f0b185f5b…