Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Revert "Add a notice about verification of keyless signing" #1487

Merged
merged 1 commit into from Aug 20, 2022

Conversation

wata727
Copy link
Member

@wata727 wata727 commented Aug 20, 2022

Reverts #1472

Cosign v1.11 now verifies the certificate chain by default when passing the --cert option.
sigstore/cosign#2139

The certificate must be generated on the GitHub Actions workflow of the terraform-linters/tflint repository, otherwise an error will occur for the malformed certificate. This leaves no room for spoofing the public key in a verification flow using Cosign.

The only attack surface is for an attacker to take control of this repository, delete existing releases, and recreate releases, which should be sufficiently difficult compared to traditional attack ways.

@wata727 wata727 merged commit 4e3a295 into master Aug 20, 2022
@wata727 wata727 deleted the revert-1472-add_notice_about_keyless_signing branch August 20, 2022 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant