sigstore-rekor-types
Python models for Rekor's API types
Decision gist · record as of 2026-08-14
Yes, if you need to interact with Rekor's API or work with Rekor data structures in Python. The package is lightweight, actively maintained, has no known vulnerabilities, and provides the type safety that pydantic offers. It is most useful as a dependency of other sigstore tools or when building custom Rekor integrations.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later.
- Low install friction with only pydantic and typing-extensions as runtime dependencies.
- Active maintenance with recent releases; last commit on 2026-08-13.
License · maintenance · safety
permissive license (permissive) — Apache License 2.0 (permissive) allows commercial use, modification, and distribution with minimal restrictions; suitable for most projects.
last release 2024-11-22 (630 days) · last repo commit 2026-08-13 · 7 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 853,212 downloads/mo, #4,897 on PyPI
Alternatives
Verify before relying
pip install sigstore-rekor-types
from sigstore_rekor_types import SomeModel
model_instance = SomeModel(**data)- Whether this package is typically used standalone or as a dependency of other sigstore tooling.
- What specific Rekor API versions or endpoints the current models cover.
- Which specific Rekor data structures are represented by the models in this package.
What it is and what it does
sigstore-rekor-types is a collection of pydantic data models that represent the types and structures used by Rekor, the transparency log at the core of the sigstore ecosystem. It provides type-safe Python bindings for Rekor's API, allowing developers to work with Rekor data in a structured, validated way. The package is intentionally minimal—it contains only the data models themselves, not client logic or higher-level tooling.
The package depends on pydantic for validation and typing-extensions for runtime type support. It is maintained as part of the sigstore project and is typically used either as a direct dependency for applications that need to interact with Rekor's API directly, or indirectly through other sigstore libraries. With no known vulnerabilities and active maintenance, it serves as a stable foundation for type-safe Rekor integration.
Use it for
- Building applications that query or consume Rekor transparency log entries with type validation.
- Integrating Rekor data structures into supply chain security workflows.
- Validating JSON responses from Rekor API calls using pydantic's built-in schema enforcement.
- Developing custom tooling that needs to work with Rekor's data types without a full client library.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to interact with Rekor's API or work with Rekor data structures in Python.
The package is lightweight, actively maintained, has no known vulnerabilities, and provides the type safety that pydantic offers. It is most useful as a dependency of other sigstore tools or when building custom Rekor integrations.
Install
sigstore-rekor-types on PyPI
Before you install
Low install friction with only pydantic and typing-extensions as runtime dependencies. Active maintenance with recent releases; last commit on 2026-08-13.
Requires Python 3.8 or later.
License in practice
Apache License 2.0 (permissive) allows commercial use, modification, and distribution with minimal restrictions; suitable for most projects.
Quickstart
pip install sigstore-rekor-types
from sigstore_rekor_types import SomeModel
model_instance = SomeModel(**data)
Verify before relying
- Whether this package is typically used standalone or as a dependency of other sigstore tooling.
- What specific Rekor API versions or endpoints the current models cover.
- Which specific Rekor data structures are represented by the models in this package.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagespydantictyping-extensions |
| Maintenance | Actively maintained 630 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 853,212 / month, #4,897 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3 |
Evidence: sigstore_rekor_types-0.0.18-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “rekor api models python”
- sigstore-rekor-typesProvides Python data models for Rekor's API types, enabling type-safe…
- sigstore-protobuf-specsProvides Python protobuf message definitions and serialization code…
- k8Provides Python type models for Kubernetes resources, generated from…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also sigstore-models · openresponses-types · sigstore · k8 · airbyte-connector-models · pydantic-geojson · django-pydantic-field · connector-sdk-types · pydantic-zarr · sigstore-protobuf-specs