Blog
- PHP signs with Sigstore now
k2gl/sigstore-sign closes the loop: keyful or keyless signing, Rekor v1 and v2, RFC 3161 timestamps, a v0.3 bundle — and the official conformance suite passes on the signing side as well as the verifying side.
- Revocation for SD-JWT VC, in PHP
k2gl/token-status-list implements the Token Status List draft — the mechanism SD-JWT VC uses to say a credential was revoked — with the draft's test vectors reproduced byte for byte.
- Eight online tools for supply-chain and identity formats
Inspect Sigstore bundles, DSSE envelopes, SLSA provenance, SD-JWTs and SSH signatures in the browser — each tool runs the same open-source PHP packages it demonstrates.
- Verify the provenance of your Composer dependencies
Sign and verify PHP package provenance with Sigstore and GitHub build attestations, end to end.