Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

support --insecure-ignore-tlog=true for cosign #2983

Open
zgfh opened this issue May 10, 2024 · 0 comments
Open

support --insecure-ignore-tlog=true for cosign #2983

zgfh opened this issue May 10, 2024 · 0 comments

Comments

@zgfh
Copy link

zgfh commented May 10, 2024

What is the problem you're trying to solve

when pull image with cosign,there is a error

i find it need --insecure-ignore-tlog=true for cosign or --private-infrastructure
see: sigstore/cosign#2808

image
image

Describe the solution you'd like

should we add --insecure-ignore-tlog=true or --private-infrastructure for nerdctl ?
like this?

nerdctl pull --verify=cosign --cosign-key cosign.pub --cosign-insecure-ignore-tlog=true release.daocloud.io/zzg/test-cosign:v1

Additional context

No response

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant