specification: API Commons DataModel specificationVersion: '0.1' provider: Cosign providerId: cosign generated: '2026-09-07' method: derived source: >- https://github.com/sigstore/cosign/blob/main/specs/SIGNATURE_SPEC.md ; https://github.com/sigstore/cosign/blob/main/specs/BUNDLE_SPEC.md ; https://github.com/sigstore/cosign/blob/main/specs/ATTESTATION_SPEC.md ; https://github.com/sigstore/cosign/blob/main/specs/SBOM_SPEC.md description: >- Derived from Cosign's own published specification documents rather than from an OpenAPI, because Cosign publishes no OpenAPI. The specs describe the entities Cosign writes into an OCI registry and into the transparency log, and they exist explicitly so other implementations can interoperate. Every field below is quoted or paraphrased from those documents; nothing is inferred. entities: - name: Signature description: >- A detached signature over a payload, stored in an OCI registry alongside the artifact it refers to. source: specs/SIGNATURE_SPEC.md properties: - name: payload type: bytes required: true description: >- The signed data. Because signatures are detached, the payload MUST contain the digest of the image it references, in a well-known location that depends on the payload format. - name: mediaType type: string required: true description: Media type of the payload. - name: signature type: string required: true description: Base64-encoded signature, generated by a supported scheme. - name: certificate type: string required: false description: >- PEM-encoded X.509 certificate. If present it MUST embed the public key that verifies the signature. This is the Fulcio-issued certificate in the keyless flow. - name: chain type: string required: false description: >- PEM-encoded, DER-formatted ASN.1 X.509 certificate chain. `certificate` MUST be present if `chain` is present. - name: Bundle description: >- A Sigstore protobuf bundle carrying a signature or a DSSE-wrapped in-toto statement together with its verification material. source: specs/BUNDLE_SPEC.md media_type: application/vnd.dev.sigstore.bundle.v0.3+json schema: https://github.com/sigstore/protobuf-specs/blob/main/protos/sigstore_bundle.proto note: >- Stored as a JSON-serialized blob in the registry, then associated with the image by an OCI Image Manifest v1.1 object per the OCI guidelines for artifact usage. Multiple attestations may be attached to one image. - name: Attestation description: >- An in-toto Statement about an artifact, DSSE-wrapped and signed. Payload type application/vnd.in-toto+json. source: specs/ATTESTATION_SPEC.md - name: Predicate description: >- The claim body inside an attestation. Cosign defines its own predicate shapes in COSIGN_PREDICATE_SPEC.md, including a vulnerability-scan predicate (COSIGN_VULN_ATTESTATION_SPEC.md), alongside standard in-toto/SLSA predicates. source: specs/COSIGN_PREDICATE_SPEC.md - name: SBOM description: >- A software bill of materials (SPDX or CycloneDX) attached to an image and retrievable with `cosign download sbom`. source: specs/SBOM_SPEC.md note: SBOM attachment as a distinct artifact type is being superseded by attestation-carried SBOMs. - name: TransparencyLogEntry description: >- The append-only Rekor record of a signing event, addressable by log index or entry UUID. Written during keyless signing; never removable. source: https://docs.sigstore.dev/logging/overview/ - name: TrustedRoot description: >- The Sigstore protobuf trusted root — CA certificates, transparency log keys and timestamp authority keys — distributed over TUF and materialised locally by `cosign initialize`. source: https://github.com/sigstore/cosign/blob/main/doc/cosign_trusted-root.md - name: SigningConfig description: >- The Sigstore protobuf signing config naming which Fulcio, Rekor and TSA instances to use for a signing operation. source: https://github.com/sigstore/cosign/blob/main/doc/cosign_signing-config.md relationships: - from: Signature to: OCIImage kind: belongs_to via: image digest embedded in the payload - from: Signature to: Certificate kind: has_one via: certificate optional: true - from: Certificate to: CertificateChain kind: has_one via: chain optional: true - from: Bundle to: OCIImage kind: belongs_to via: OCI Image Manifest v1.1 subject/referrer association - from: Bundle to: Attestation kind: has_one via: DSSE-wrapped in-toto statement payload - from: Attestation to: Predicate kind: has_one via: in-toto Statement predicate - from: OCIImage to: Bundle kind: has_many via: multiple attestations may be attached to one image - from: Signature to: TransparencyLogEntry kind: has_one via: Rekor entry UUID / log index recorded at signing time optional: true - from: TransparencyLogEntry to: Certificate kind: belongs_to via: the Fulcio certificate whose identity signed the entry - from: SigningConfig to: TrustedRoot kind: references via: the CA, log and TSA identities a verification must trust storage: registry_layout: >- Signatures and attestations are stored in the same OCI repository as the artifact. BUNDLE_SPEC.md describes the current path: the bundle is uploaded as a blob (POST /v2//blobs/uploads/?digest=, Content-Type application/octet-stream) and then referenced by a manifest that associates it with the image. SIGNATURE_SPEC.md describes the older tag-based discovery scheme. identifiers: - kind: OCI digest form: sha256: - kind: Rekor entry UUID form: hex string, addressable at /api/v1/log/entries/{entryUUID} - kind: Rekor log index form: integer, addressable at /api/v1/log/entries?logIndex={n}