Model lifecycle & governance
OpenSSF Model Signing (OMS) / model-transparency
OpenSSF-backed specification with an Apache-2.0 library and CLI that signs and verifies machine learning model artifacts using Sigstore, self-signed certificates, public keys or PKCS#11 devices, producing signature bundles that let consumers check model integrity and provenance before deployment or reuse.
open_source · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Model lifecycle & governance · Data governance & privacy · Agent security & threat detection
Useful conversation with: ML platform engineer, Supply chain security lead, CISO.
Ask for a demonstration
Demonstrate signing a multi-gigabyte model with Sigstore and verifying the signature in a deployment pipeline gate, including what the bundle attests to.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
OpenSSF states the project provides a library and CLI for signing and verification of ML models, supporting any model format and size and several PKI options including Sigstore, self-signed certificates and public/private key pairs, with signatures checkable whenever a model is uploaded, deployed or reused.
Limit: Signatures attest to artifact integrity and signer identity; they say nothing about model quality, safety or training-data legality.
Source s1
Documented by provider
The sigstore/model-transparency repository states the signing process produces a Sigstore bundle stored as JSON containing a DSSE envelope with an in-toto statement whose subjects are file path and digest pairs, and supports PKCS#11 devices.
Limit: Repository documents the mechanism; adoption across model hubs is not evidenced here.
Source s2
Documented by provider
GitHub metadata for sigstore/model-transparency records Apache-2.0 licensing, a non-archived repository and commits in September 2026.
Limit: The OpenSSF project page itself does not state a license.
Source s3
Limitations to discuss
- Specification and implementation live in different organisations (OpenSSF spec, sigstore repo)
- Signature verification is only useful with a policy that enforces it
Sources
- OpenSSF Model Signing (OMS) · OpenSSF · official product
Access date reported by researcher: 2026-09-06 - sigstore/model-transparency · Sigstore / GitHub · official repository
Access date reported by researcher: 2026-09-06 - GitHub REST API repository record · GitHub · official repository
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction