Conversation
3eb2c02 to
0f36075
Compare
|
The first commit contains the applied patch and tests, the second covers the changes needed to upstream it. I will squash them at the end. |
gerrod3
left a comment
There was a problem hiding this comment.
I'm having second thoughts about moving this patch over. I think we should spend some more time thinking about the feature and what would be useful to more people.
| standard Sigstore path. Attestations without certificates are verified | ||
| against a custom public key configured via ATTESTATION_VERIFICATION_KEY. | ||
| Currently, it supports RSA PKCS1v15 signatures and SLSA v0.2 provenance | ||
| publisher enrichment. |
There was a problem hiding this comment.
The publisher enrichment is technically a side-effect of the method. Not sure it's the best thing to copy.
| stmt = _verify_statement_subject(attestation, dist) | ||
| _enrich_publisher_from_statement(stmt, publisher) | ||
| if verification_key: | ||
| _verify_signature(attestation, verification_key) |
There was a problem hiding this comment.
Only one key to verify against across all repositories and all domains. I wonder if we could do something better. What services has is custom built for their use-case, so I don't really want to just move it over as is.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
📜 Checklist
See: Pull Request Walkthrough