Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[intoto] Support intoto v0.0.2 type in rekor for upload and verification #2219

Closed
asraa opened this issue Sep 1, 2022 · 4 comments
Closed
Assignees
Labels
enhancement New feature or request

Comments

@asraa
Copy link
Contributor

asraa commented Sep 1, 2022

Description

This type allows full verification of the intoto entry. See sigstore/rekor#973

We can migrate upload support to v0.0.2 and continue supporting v0.0.1 for verification. I can stage the PR for whenever Rekor server is deployed with v0.0.2 support.

@asraa asraa added the enhancement New feature or request label Sep 1, 2022
@asraa asraa self-assigned this Sep 1, 2022
@haydentherapper
Copy link
Contributor

We pushed the new release of Rekor to staging and ran into this. This is a blocker for releasing the new Rekor since we no longer allow the upload of 0.0.1 intoto entries, unless we want to ease that restriction.

@bobcallaway

@asraa
Copy link
Contributor Author

asraa commented Sep 6, 2022

This is a blocker for releasing the new Rekor since we no longer allow the upload of 0.0.1 intoto entries, unless we want to ease that restriction.

What about old clients using old cosign versions? (or sigstore-python/npm etc)

@haydentherapper
Copy link
Contributor

This is likely an issue. Clients will need to update, so we will need to give them the time to do so. I think we should relax the restriction for now so we can unblock Rekor updates.

@asraa asraa mentioned this issue Oct 25, 2022
3 tasks
@haydentherapper
Copy link
Contributor

No longer needed, as we use the DSSE type now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants