rekor-cli
« Back to VersTracker
Description:
CLI for interacting with Rekor
Type: Formula  |  Latest Version: 1.4.3@0  |  Tracked Since: Nov 14, 2025
Links: Homepage  |  @sigstore_dev  |  formulae.brew.sh
Category: Security
Tags: security supply-chain sigstore transparency-log cli devops
Install: brew install rekor-cli
About:
The rekor-cli is the official command-line interface for the Rekor transparency log, a key component of the Sigstore ecosystem. It allows developers to create, verify, and query entries in a cryptographically secure, tamper-evident public ledger for software artifacts. Its main value is providing verifiable proof of existence and integrity for software releases and build attestations.
Key Features:
  • Submit and verify software artifact signatures to the transparency log
  • Query the log for entries by artifact hash, public key, or other properties
  • Generate cryptographic proofs of inclusion for log entries
  • Integrates with the broader Sigstore suite (Fulcio, Cosign)
  • Supports multiple signing and attestation formats
Use Cases:
  • Verifying the provenance and integrity of open-source software dependencies
  • Creating a publicly auditable record of software build and release events
  • Enhancing supply chain security by providing non-repudiable evidence for artifacts
Alternatives:
  • cosign – Primarily for signing and verifying container images, but can interact with Rekor; rekor-cli is the general-purpose tool for direct log operations.
Version History
Detected Version Rev Change Commit
Dec 27, 2025 5:17pm 1.4.3 0 VERSION_BUMP f25d71b4
Nov 14, 2025 11:52pm 0 VERSION_BUMP cb2d84a2
Oct 9, 2025 8:06pm 0 VERSION_BUMP 39612cbb
Sep 16, 2025 7:39pm 0 VERSION_BUMP 014717b1
Sep 15, 2025 1:33pm 0 VERSION_BUMP b19996ad
Jan 16, 2025 11:07pm 0 VERSION_BUMP 95f6d728
Sep 14, 2024 1:01am 0 VERSION_BUMP ac8ea7ff