notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
I started running short on disk space for the non-production FreshPorts hosts. This time, I have decided to ask for donations. See my recent blog post which points to my Patreon account.
Port details
cosign Signing OCI containers and other artifacts using Sigstore
2.6.1_1 security on this many watch lists=0 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 2.6.0Version of this port present on the latest quarterly branch.
Maintainer: bofh@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2025-05-04 18:49:45
Last Update: 2025-10-08 00:41:39
Commit Hash: 2e7587a
License: APACHE20
WWW:
https://www.sigstore.dev/
Description:
Cosign aims to make signatures invisible infrastructure. Cosign supports: - "Keyless signing" with the Sigstore public good Fulcio certificate authority and Rekor transparency log (default) - Hardware and KMS signing - Signing with a cosign generated encrypted private/public keypair - Container Signing, Verification and Storage in an OCI registry. - Bring-your-own PKI
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
Expand this list (4 items)
Collapse this list.
  1. bin/cosign
  2. /usr/local/share/licenses/cosign-2.6.1_1/catalog.mk
  3. /usr/local/share/licenses/cosign-2.6.1_1/LICENSE
  4. /usr/local/share/licenses/cosign-2.6.1_1/APACHE20
Collapse this list.
USE_RC_SUBR (Service Scripts)
  • no SUBR information found for this port
Dependency lines:
  • cosign>0:security/cosign
To install the port:
cd /usr/ports/security/cosign/ && make install clean
To add the package, run one of these commands:
  • pkg install security/cosign
  • pkg install cosign
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: cosign
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1759523978 SHA256 (go/security_cosign/cosign-v2.6.1/v2.6.1.mod) = 4d6e9e11c0efec4ed8d03058cd1b73a0f9a830b804fb59a42890e6ea7f91fea8 SIZE (go/security_cosign/cosign-v2.6.1/v2.6.1.mod) = 17701

Expand this list (2 items)

Collapse this list.

SHA256 (go/security_cosign/cosign-v2.6.1/v2.6.1.zip) = 8821408a71dba7b6ed4b94cac23b8e0679a9d23419d83a3e4b303796d920c6d3 SIZE (go/security_cosign/cosign-v2.6.1/v2.6.1.zip) = 1367164

Collapse this list.


Packages (timestamps in pop-ups are UTC):
cosign
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest2.6.02.6.0-2.6.02.6.0---
FreeBSD:13:quarterly2.5.12.6.0-2.5.12.6.0---
FreeBSD:14:latest2.5.3_12.6.1-2.5.3_12.6.1---
FreeBSD:14:quarterly2.5.12.6.0-2.5.12.6.0---
FreeBSD:15:latest2.6.02.6.0n/a-n/a---
FreeBSD:15:quarterly--n/a-n/a---
FreeBSD:16:latest-2.6.1n/a-n/a---
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. go124 : lang/go124
Fetch dependencies:
  1. go124 : lang/go124
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
security_cosign
USES:
cpe go:modules zip
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. https://proxy.golang.org/github.com/sigstore/cosign/v2/@v/
Collapse this list.

Number of commits found: 10

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
2.6.1_1
08 Oct 2025 00:41:39
commit hash: 2e7587aaf8e7f893fd2025d55f66de088427b180commit hash: 2e7587aaf8e7f893fd2025d55f66de088427b180commit hash: 2e7587aaf8e7f893fd2025d55f66de088427b180commit hash: 2e7587aaf8e7f893fd2025d55f66de088427b180 files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
many: Bump dependent ports after go124 update
2.6.1
04 Oct 2025 11:59:18
commit hash: 8878d4e0bc9f1f6bcf1fd40ebd6c22bc782f2f1fcommit hash: 8878d4e0bc9f1f6bcf1fd40ebd6c22bc782f2f1fcommit hash: 8878d4e0bc9f1f6bcf1fd40ebd6c22bc782f2f1fcommit hash: 8878d4e0bc9f1f6bcf1fd40ebd6c22bc782f2f1f files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.6.0=>2.6.1

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.6.1
2.6.0
13 Sep 2025 21:03:18
commit hash: 5a35c1f026e42e09f3a663e0acae75215706a765commit hash: 5a35c1f026e42e09f3a663e0acae75215706a765commit hash: 5a35c1f026e42e09f3a663e0acae75215706a765commit hash: 5a35c1f026e42e09f3a663e0acae75215706a765 files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.3=>2.6.0

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.6.0
2.5.3_2
04 Sep 2025 17:53:24
commit hash: 31a5a229a778dc5f458cb8887954f192d846e0e3commit hash: 31a5a229a778dc5f458cb8887954f192d846e0e3commit hash: 31a5a229a778dc5f458cb8887954f192d846e0e3commit hash: 31a5a229a778dc5f458cb8887954f192d846e0e3 files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
many: Bump go ports for go-1.24.7
2.5.3_1
07 Aug 2025 00:02:46
commit hash: 53610681ea46b375186fc68723dcc335051ef9b4commit hash: 53610681ea46b375186fc68723dcc335051ef9b4commit hash: 53610681ea46b375186fc68723dcc335051ef9b4commit hash: 53610681ea46b375186fc68723dcc335051ef9b4 files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
go ports: Bump for 1.24.6
2.5.3
18 Jul 2025 21:35:10
commit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6dcommit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6dcommit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6dcommit hash: 1be8799a621231ef4e72c0c15fd5c399ac05fe6d files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.2=>2.5.3

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.5.3
2.5.2_1
09 Jul 2025 16:11:00
commit hash: 275975297bc1002e96f88f503cf18dea17df847ecommit hash: 275975297bc1002e96f88f503cf18dea17df847ecommit hash: 275975297bc1002e96f88f503cf18dea17df847ecommit hash: 275975297bc1002e96f88f503cf18dea17df847e files touched by this commit
Adam Weinberger (adamw) search for other commits by this committer
many: Bump PORTREVISION for go-1.24.5 update
2.5.2
02 Jul 2025 16:29:33
commit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bbcommit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bbcommit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bbcommit hash: 1689e3eb1cfd498da66863d5aa518168a66a63bb files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.1=>2.5.2

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.5.2
2.5.1
30 Jun 2025 16:11:12
commit hash: ee522035c078de598f383ccc719d74ec15b19772commit hash: ee522035c078de598f383ccc719d74ec15b19772commit hash: ee522035c078de598f383ccc719d74ec15b19772commit hash: ee522035c078de598f383ccc719d74ec15b19772 files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: Update version 2.5.0=>2.5.1

Changelog: https://github.com/sigstore/cosign/releases/tag/v2.5.1
2.5.0
04 May 2025 18:44:46
commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389commit hash: e4a9ef0dd38bcab6535b4d6ad4bdc8c3f3abd389 files touched by this commit
Muhammad Moinur Rahman (bofh) search for other commits by this committer
security/cosign: New port

Signing OCI containers and other artifacts using Sigstore

Cosign aims to make signatures invisible infrastructure.

Cosign supports:
- "Keyless signing" with the Sigstore public good Fulcio certificate
   authority and Rekor transparency log (default)
- Hardware and KMS signing
- Signing with a cosign generated encrypted private/public keypair
- Container Signing, Verification and Storage in an OCI registry.
- Bring-your-own PKI

WWW: https://github.com/sigstore/cosign

Number of commits found: 10