Linux workstation

Upstream software project

rekor

Signature Transparency Log (server)

About rekor

Signature Transparency Log (server)

This project links 20 native package records across 7 recorded operating-system releases. Compare the retained versions and architectures below, then open the package for your own release.

These are catalog observations, not a guarantee of installation, compatibility, or upstream support.

Project pictures and package coverage

rekor repository preview from GitHub
Project repository preview, supplied by GitHub. Open source repository
Alpine Linux 3.21: 5 package records; Alpine Linux 3.22: 5 package records; Alpine Linux 3.23: 5 package records; Debian 13 (Trixie): 2 package records; openSUSE Leap 15.6: 1 package records; openSUSE Leap 16.0: 1 package records; openSUSE Tumbleweed: 1 package records. Catalog coverage diagram, not an application screenshot.rekor: recorded package coverageAlpine Linux 3.215 recordsAlpine Linux 3.225 recordsAlpine Linux 3.235 recordsDebian 13 (Trixie)2 recordsopenSUSE Leap 15.61 recordsopenSUSE Leap 16.01 recordsopenSUSE Tumbleweed1 records
OpenFactory diagram of linked package records. It is not an application screenshot.

Project identity

Project
rekor
Publisher
Not authoritatively mapped
Native package records
20
Operating systems
alpine-linux-3-21, alpine-linux-3-22, alpine-linux-3-23, debian-13, opensuse-leap-15-6, opensuse-leap-16-0, opensuse-tumbleweed
License expression
Apache-2.0
Metadata completeness
70/100 (not a software quality rating)
Source repository
Open source repository

Source-reported description

The fullest retained description is shown with its source. Distribution packaging descriptions may include downstream details.

Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. Rekor will enable software maintainers and build systems to record signed metadata to an immutable record. Other parties can then query said metadata to enable them to make informed decisions on trust and non-repudiation of an object's lifecycle. For more details visit the sigstore website The Rekor project provides a restful API based server for validation and a transparency log for storage. A CLI application is available to make and verify entries, query the transparency log for inclusion proof, integrity verification of the transparency log or retrieval of entries by either public key or artifact. Rekor fulfils the signature transparency role of sigstore's software signing infrastructure. However, Rekor can be run on its own and is designed to be extensible to working with different manifest schemas and PKI tooling.

Description source

Packages by operating system

Compare recorded versions, then open a package for dependency, file, checksum, and repository evidence. Version strings are distribution-specific, not a ranking of newer software.

Alpine Linux 3.21

  1. rekor

    Alpine Linux 3.21 / source rekor

    1.3.6-r5

    Signature transparency log

    aarch64x86_64v3.21
  2. rekor-bash-completion

    Alpine Linux 3.21 / source rekor

    1.3.6-r5

    Bash completions for rekor

    aarch64x86_64v3.21
  3. rekor-fish-completion

    Alpine Linux 3.21 / source rekor

    1.3.6-r5

    Fish completions for rekor

    aarch64x86_64v3.21
  4. rekor-server

    Alpine Linux 3.21 / source rekor

    1.3.6-r5

    Signature Transparency Log (server)

    aarch64x86_64v3.21
  5. rekor-zsh-completion

    Alpine Linux 3.21 / source rekor

    1.3.6-r5

    Zsh completions for rekor

    aarch64x86_64v3.21

Alpine Linux 3.22

  1. rekor

    Alpine Linux 3.22 / source rekor

    1.3.9-r8

    Signature transparency log

    aarch64x86_64v3.22
  2. rekor-bash-completion

    Alpine Linux 3.22 / source rekor

    1.3.9-r8

    Bash completions for rekor

    aarch64x86_64v3.22
  3. rekor-fish-completion

    Alpine Linux 3.22 / source rekor

    1.3.9-r8

    Fish completions for rekor

    aarch64x86_64v3.22
  4. rekor-server

    Alpine Linux 3.22 / source rekor

    1.3.9-r8

    Signature Transparency Log (server)

    aarch64x86_64v3.22
  5. rekor-zsh-completion

    Alpine Linux 3.22 / source rekor

    1.3.9-r8

    Zsh completions for rekor

    aarch64x86_64v3.22

Alpine Linux 3.23

  1. rekor

    Alpine Linux 3.23 / source rekor

    1.4.2-r6

    Signature transparency log

    aarch64x86_64v3.23
  2. rekor-bash-completion

    Alpine Linux 3.23 / source rekor

    1.4.2-r6

    Bash completions for rekor

    aarch64x86_64v3.23
  3. rekor-fish-completion

    Alpine Linux 3.23 / source rekor

    1.4.2-r6

    Fish completions for rekor

    aarch64x86_64v3.23
  4. rekor-server

    Alpine Linux 3.23 / source rekor

    1.4.2-r6

    Signature Transparency Log (server)

    aarch64x86_64v3.23
  5. rekor-zsh-completion

    Alpine Linux 3.23 / source rekor

    1.4.2-r6

    Zsh completions for rekor

    aarch64x86_64v3.23

Debian 13 (Trixie)

  1. golang-github-sigstore-rekor-dev

    Debian 13 (Trixie) / golang / source rekor

    1.3.9-1

    Software Supply Chain Transparency Log (library)

    alltrixie
  2. rekor

    Debian 13 (Trixie) / golang / source rekor

    1.3.9-1+b5

    Software Supply Chain Transparency Log (program)

    amd64arm64trixie

openSUSE Leap 15.6

  1. rekor

    openSUSE Leap 15.6 / Unspecified / source rekor

    1.3.5-150400.4.19.1

    Supply Chain Transparency Log

    aarch64ppc64les390xx86_64leap-15.6

openSUSE Leap 16.0

  1. rekor

    openSUSE Leap 16.0 / Unspecified / source rekor

    1.3.10-160000.2.2

    Supply Chain Transparency Log

    aarch64ppc64les390xx86_64leap-16.0

openSUSE Tumbleweed

  1. rekor

    openSUSE Tumbleweed / Unspecified / source rekor

    1.5.4-1.1

    Supply Chain Transparency Log

    x86_64tumbleweed

Project resources and further reading

Mapping provenance

Only source-backed identity signals create public cross-OS links. A reviewer can later approve or dispute an inferred relationship without rewriting native package history.

No field-level source record is published yet.