Skip to content
This repository was archived by the owner on Jan 6, 2026. It is now read-only.

Add support for verifying attestations (updated) - #49

Open
evenh wants to merge 12 commits into
sigstore:mainfrom
evenh:updated-verify-attestations
Open

Add support for verifying attestations (updated)#49
evenh wants to merge 12 commits into
sigstore:mainfrom
evenh:updated-verify-attestations

Conversation

@evenh

@evenh evenh commented Mar 29, 2023

Copy link
Copy Markdown

An updated version of #8

ribbybibby and others added 12 commits January 11, 2022 16:06
Different images will require different verification options. This
commit adds configuration that allows you to define different
'verifiers' for specific image references, or image reference patterns.

At the moment it supports verification by public key, or the existing
options, but should be expanded to include all supported options.

Also modifies the response from the provider to include an error
per-image checked, rather than returning any error as a 'system' error.

I've also removed the _invalid suffix from the key returned in the
response when there's an error. The presence of the 'error' field
indicates this better, I think.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
An image can have multiple signatures and therefore in some cases you'll
want multiple verifiers for the same images.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Modify the configuration so that multiple verifiers can be associated
directly with an image reference/pattern. Images will only be verified
for the first pattern they match.

This makes it possible to provide multiple verification options for a
specific image pattern/reference but also fall through to a less-specific
pattern (with different verification options) for images that don't
match a more specific pattern.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Checking the count of errors is enough.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Signed-off-by: Even Holthe <even.holthe@bekk.no>
@evenh
evenh force-pushed the updated-verify-attestations branch from 3f91518 to ad3dc7b Compare March 29, 2023 12:32
@evenh evenh changed the title Support different verification options per image More Add support for verifying attestations (updated) Mar 29, 2023
@evenh evenh changed the title More Add support for verifying attestations (updated) Add support for verifying attestations (updated) Mar 29, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants