notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

Port details
cosign Signing OCI containers and other artifacts using Sigstore
2.5.3_1 security on this many watch lists=0 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 2.5.0Version of this port present on the latest quarterly branch.
Maintainer: bofh@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2025-05-04 18:49:45
Last Update: 2025-08-07 00:02:46
Commit Hash: 5361068
License: APACHE20
WWW:
https://www.sigstore.dev/
Description:
Cosign aims to make signatures invisible infrastructure. Cosign supports: - "Keyless signing" with the Sigstore public good Fulcio certificate authority and Rekor transparency log (default) - Hardware and KMS signing - Signing with a cosign generated encrypted private/public keypair - Container Signing, Verification and Storage in an OCI registry. - Bring-your-own PKI
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (4 items)
Collapse this list.
  1. bin/cosign
  2. /usr/local/share/licenses/cosign-2.5.3_1/catalog.mk
  3. /usr/local/share/licenses/cosign-2.5.3_1/LICENSE
  4. /usr/local/share/licenses/cosign-2.5.3_1/APACHE20
Collapse this list.
Dependency lines:
  • cosign>0:security/cosign
To install the port:
cd /usr/ports/security/cosign/ && make install clean
To add the package, run one of these commands:
  • pkg install security/cosign
  • pkg install cosign
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: cosign
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1752874321 SHA256 (go/security_cosign/cosign-v2.5.3/v2.5.3.mod) = 3d3e90c2ad6b9f1dc45c9f83c5408d4296d80ae3728998504d9d3e077dd19afe SIZE (go/security_cosign/cosign-v2.5.3/v2.5.3.mod) = 16693

Expand this list (2 items)

Collapse this list.

SHA256 (go/security_cosign/cosign-v2.5.3/v2.5.3.zip) = e0158a5721ba7c8e2b775af499c07d89957ae42177a1794c8382e1e91901b531 SIZE (go/security_cosign/cosign-v2.5.3/v2.5.3.zip) = 1335557

Collapse this list.


Packages (timestamps in pop-ups are UTC):
cosign
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest2.5.32.5.3_1-2.5.32.5.3_1---
FreeBSD:13:quarterly2.5.12.5.1-2.5.12.5.1---
FreeBSD:14:latest2.5.32.5.3_1-2.5.22.5.3_1---
FreeBSD:14:quarterly2.5.12.5.1-2.5.12.5.1---
FreeBSD:15:latest--n/a2.5.0n/a---
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. go124 : lang/go124
Fetch dependencies:
  1. go124 : lang/go124
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_cosign
USES:
cpe go:modules zip
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. https://proxy.golang.org/github.com/sigstore/cosign/v2/@v/
Collapse this list.

Number of commits found: 6

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
2.5.3_1
07 Aug 2025 00:02:46
commit hash: 53610681ea46b375186fc68723dcc335051ef9b4commit hash: 53610681ea46b375186fc68723dcc335051ef9b4commit hash: 53610681ea46b375186fc68723dcc335051ef9b4commit hash: 53610681ea46b375186fc68723dcc335051ef9b4 files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
go ports: Bump for 1.24.6
2.5.3
18 Jul 2025 21:35:10
commit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6dcommit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6dcommit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6dcommit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6d files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.2=>2.5.3

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.5.3
2.5.2_1
09 Jul 2025 16:11:00
commit hash: 275975297bc1002e96f88f503cf18dea17df847ecommit hash: 275975297bc1002e96f88f503cf18dea17df847ecommit hash: 275975297bc1002e96f88f503cf18dea17df847ecommit hash: 275975297bc1002e96f88f503cf18dea17df847e files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
many: Bump PORTREVISION for go-1.24.5 update
2.5.2
02 Jul 2025 16:29:33
commit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bbcommit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bbcommit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bbcommit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bb files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.1=>2.5.2

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.5.2
2.5.1
30 Jun 2025 16:11:12
commit hash: ee522035c078de598f383ccc719d74ec15b19772commit hash: ee522035c078de598f383ccc719d74ec15b19772commit hash: ee522035c078de598f383ccc719d74ec15b19772commit hash: ee522035c078de598f383ccc719d74ec15b19772 files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.0=>2.5.1

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.5.1
2.5.0
04 May 2025 18:44:46
commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389 files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: New port

Signing OCI containers and other artifacts using Sigstore

Cosign aims to make signatures invisible infrastructure.

Cosign supports:
- "Keyless signing" with the Sigstore public good Fulcio certificate
   authority and Rekor transparency log (default)
- Hardware and KMS signing
- Signing with a cosign generated encrypted private/public keypair
- Container Signing, Verification and Storage in an OCI registry.
- Bring-your-own PKI

WWW: https://github.com/sigstore/cosign

Number of commits found: 6