k2gl/tuf dependents (1) Order by: name | downloads Show: all | require | require-dev

  • PHP

    k2gl/sigstore-verify

    Offline, fail-closed PHP verifier for Sigstore bundles: certificate chain to a Fulcio root, DSSE signature, Rekor transparency-log proof and identity policy, returning a verified in-toto Statement.

    Latest version requires k2gl/tuf ^1.0