Model lifecycle & governance

OpenSSF Model Signing (OMS) / model-transparency

OpenSSF-backed specification with an Apache-2.0 library and CLI that signs and verifies machine learning model artifacts using Sigstore, self-signed certificates, public keys or PKCS#11 devices, producing signature bundles that let consumers check model integrity and provenance before deployment or reuse.

open_source · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Model lifecycle & governance · Data governance & privacy · Agent security & threat detection

Useful conversation with: ML platform engineer, Supply chain security lead, CISO.

Ask for a demonstration

Demonstrate signing a multi-gigabyte model with Sigstore and verifying the signature in a deployment pipeline gate, including what the bundle attests to.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

OpenSSF states the project provides a library and CLI for signing and verification of ML models, supporting any model format and size and several PKI options including Sigstore, self-signed certificates and public/private key pairs, with signatures checkable whenever a model is uploaded, deployed or reused.

Limit: Signatures attest to artifact integrity and signer identity; they say nothing about model quality, safety or training-data legality.

Source s1

Documented by provider

The sigstore/model-transparency repository states the signing process produces a Sigstore bundle stored as JSON containing a DSSE envelope with an in-toto statement whose subjects are file path and digest pairs, and supports PKCS#11 devices.

Limit: Repository documents the mechanism; adoption across model hubs is not evidenced here.

Source s2

Documented by provider

GitHub metadata for sigstore/model-transparency records Apache-2.0 licensing, a non-archived repository and commits in September 2026.

Limit: The OpenSSF project page itself does not state a license.

Source s3

Limitations to discuss

Sources

  1. OpenSSF Model Signing (OMS) · OpenSSF · official product
    Access date reported by researcher: 2026-09-06
  2. sigstore/model-transparency · Sigstore / GitHub · official repository
    Access date reported by researcher: 2026-09-06
  3. GitHub REST API repository record · GitHub · official repository
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction