What is sign?
67/100
Trust Score (B-)
⚠️ Use Caution
sign is a npm that Sigstore signing library. It has a Nerq Trust Score of 67/100 (B-). 0 GitHub stars. Published by bdehamer. Last analyzed September 2026.
Why This Score
- ⚠️ Security: 0/100 — Some security concerns
- ⚠️ Maintenance: 0/100 — Maintenance activity is low
- ⚠️ Community: 0 stars, 0 downloads — Growing community
- ⚠️ Transparency: License: Not specified — No license specified
Trust & Safety Overview
67
TRUST SCORE
B-
GRADE
0
STARS
0
DOWNLOADS
What sign Does
sign is a npm in the npm category. Sigstore signing library. It is published by bdehamer and has no specified license. With 0 GitHub stars and 0 downloads, it has a small community of users and contributors.
Who Should Use sign
sign is suitable for evaluation and non-critical use. Review the trust score breakdown before using in production.
Details
| Author | bdehamer |
|---|---|
| Category | npm |
| License | Not specified |
| Type | npm |
| Source | View on GitHub |
| Security Score | 0/100 |
| Activity Score | 0/100 |
How to Get Started
Check the trust score before installing:
curl nerq.ai/v1/preflight?target=sigstore-sign
Setup guide · Full safety report · Production review · Is it safe?
Frequently Asked Questions
What is sign used for?
sign is a npm tool. Sigstore signing library.
Is sign free?
License: Check project page. sign has 0 GitHub stars.
Is sign safe?
sign has a Nerq Trust Score of 67/100 (B-). Use with caution.
What are alternatives to sign?
Top alternatives: . See full comparison.
Safety Report Is It Safe?
Alternatives Prediction
Trending Leaderboard
Discover MCP Servers
Packages Models
Stats API
Last updated September 2026. Trust scores based on automated analysis of public data.