Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update verification steps for the latest Cosign #1449

Merged
merged 1 commit into from
Jul 27, 2022
Merged

Conversation

wata727
Copy link
Member

@wata727 wata727 commented Jul 27, 2022

In Cosign v1.10, the --certificate-github-workflow-repository option has been added to allow verification of OIDC subject claims on certificates.

Ideally, it's better to get the certificate from Rekor (COSIGN_EXPERIMENTAL=1), but it's also safe if you can validate the certificate chain, even if downloaded individually from GitHub. We will adopt a way to download certificates individually because it is more stable.

@wata727 wata727 merged commit f887710 into master Jul 27, 2022
@wata727 wata727 deleted the wata727-patch-1 branch July 27, 2022 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant