Package Health

k2gl/sigstore-verify

Offline, fail-closed PHP verifier for Sigstore bundles: certificate chain to a Fulcio root, DSSE signature, Rekor transparency-log proof and identity policy, returning a verified in-toto Statement.

Latest 0.6.0PackagistPackagist

71%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

95

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

19

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nickolay Harin

Direct Dependencies

DependencyLast ReleaseScore
k2gl/tuf
Version ^1.0
phpseclib/phpseclib
Version ^3.0
k2gl/in-toto-attestation
Version ^1.0

Weekly Downloads

Info

Last Published
10 hours ago
Created
2 days ago