Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add test for sigstore-rs #1433

Open
jku opened this issue Feb 3, 2025 · 1 comment · Fixed by #1434
Open

Add test for sigstore-rs #1433

jku opened this issue Feb 3, 2025 · 1 comment · Fixed by #1434
Labels
enhancement New feature or request

Comments

@jku
Copy link
Member

jku commented Feb 3, 2025

There's a few reasons why sigstore-rs is not yet tested (is experimental, does not support staging, does not support configuring TUF urls, the "bundle" example that we could use has not been released yet) but we keep breaking sigstore-rs (#1431) so we should still do it.

I will push a draft PR. It's a little tricky to test right now.

@jku jku added the enhancement New feature or request label Feb 3, 2025
@jku jku linked a pull request Feb 3, 2025 that will close this issue
@jku
Copy link
Member Author

jku commented Feb 6, 2025

An attempt was made but:

  • sigstore-rs does not support signing in GitHub Actions so we need to test verify only and use a bundle made by another client
  • There is a signature bundle available for this purpose. It's produced by sigstore-python so is bundle v0.3: sigstore-rs only supports <=0.2

so a sigstore-rs test is not currently included.

Either sigstore-rs needs to support bundle v0.3 (or GHA signing) or we need some changes in our testing infra

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant