Rekor
Rekor is Sigstore’s transparency log: a tamper-resistant, append-only ledger of signing metadata from software supply chains. You can query it with the rekor-cli command-line tool to verify that an artifact’s signature was recorded.
To learn how Rekor works and why a transparency log matters, read What is Rekor? in Supply Chain Security 101. The pages in this section show you how to install Rekor, query it, upload signed metadata, and run your own Rekor instance.