[](https://github.com/sigstore/sigstore-rs/actions/workflows/tests.yml) | [](https://sigstore.github.io/sigstore-rs/sigstore) | [](https://opensource.org/licenses/Apache-2.0)
This is an experimental crate to interact with [sigstore](https://sigstore.dev/).
This is under high development, many features and checks are still missing.
## Features
### Verification
The crate implements the following verification mechanisms:
* Verify using a given key
* Verify bundle produced by transparency log (Rekor)
* Verify signature produced in keyless mode, using Fulcio Web-PKI
Signature annotations and certificate email can be provided at verification time.
#### Known limitations
* The crate does not handle verification of attestations yet.
## Examples
The `examples` directory contains demo programs using the library.
## Security
Should you discover any security issues, please refer to sigstores [security
process](https://github.com/sigstore/community/security/policy)