AI Potluck
Back to Gap Map Product / UX / Assurance & compliance evidence

OpenSSF Model Signing

Sigstore
open source / Overall score: 3.2

OpenSSF Model Signing signs machine-learning models and verifies those signatures, so a user can check a model's integrity and provenance for themselves rather than trusting whoever trained it. It signs with Sigstore's keyless flow, with public keys or certificates, or through PKCS #11 devices, and emits a Sigstore bundle following the OpenSSF Model Signing specification. It is developed under the Sigstore project.

Tagged independently verifiable: a signature over the model's file digests checks offline or against Sigstore's transparency log.

Openness

5 high confidence
5.0
license
Apache-2.0(OSI)
source
public
core features withheld
no

The library and CLI are published under Apache-2.0 within the Sigstore project, an open-source effort of the OpenSSF, so no vendor stands behind it with a paid edition.

Adoption

2 medium confidence
2.0

PyPI downloads of model-signing, the project's own package, measure its use. Signing done inside registries such as NVIDIA's NGC does not show up in them.

Capability

4 high confidence
4.0

The signature lets anyone confirm a model is the one its publisher signed, without asking the publisher, and NVIDIA signs its NGC catalog to the same specification. It attests who published the weights, not how they were produced, which keeps it a step below NVIDIA's hardware attestation.

Verified 2026-09-26