Deps.dev vs Sigstore
Deps.devSupply Chain Security
FreePublished price
SigstoreSupply Chain Security
FreePublished price
Deps.dev Supply Chain Security Understand your dependencies | Sigstore Supply Chain Security sign. verify. protect. Make sure your software is what it claims to be. | |
|---|---|---|
| Overview | ||
| Category | Supply Chain Security | Supply Chain Security |
| What it is | Google service for understanding dependencies of open source packages with security advisories and license information. | Open-source project providing free code signing and verification infrastructure for software supply chain integrity and provenance. |
| Pricing | ||
| Published price | Free Free service operated by Google (Open Source Insights). No paid tier; the web UI, API, and BigQuery dataset are provided at no charge. Not a commercial product. | Free Sigstore is a free, open-source project under the OpenSSF (Linux Foundation) with no paid tier. Its public-good signing infrastructure (Fulcio, Rekor, cosign) is free to use; ther… |
| Pricing model | Free | Not available |
| Free options | Free plan · No free trial | Free plan · No free trial |
| Deal on Cubbie | None right now | None right now |
| Company | ||
| Founded | 2021 | 2021 |
| Team size | 10000+ employees | 11-50 employees |
| Headquarters | Mountain View, CA | Mountain View, CA |