-
Notifications
You must be signed in to change notification settings - Fork 59
Offline Rekor bundle generation and verification #247
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 33 commits
Commits
Show all changes
40 commits
Select commit
Hold shift + click to select a range
fd95140
_cli: flag scaffolding for offline rekor verification
woodruffw 51d611d
_cli: more scaffolding
woodruffw bcf6616
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw e85b5b9
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw 5aaeaf3
sigstore: refactor RekorEntry/SET verification for offline bundles
woodruffw 6139a99
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw 8c96fcd
_cli: add envvar defaults for new flags
woodruffw 96f3af9
README: update `sigstore verify --help`
woodruffw 98529de
_cli: handle `verify --offline` correctly
woodruffw d2c52c8
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw 5d2e6ae
rekor/client: fix docstring
woodruffw 988e75a
_cli: Add `rekor` suffix to offline bundle flags/options
woodruffw 446cf31
README: update `sigstore verify`
woodruffw 94db410
_verify: elaborate on the properties of a non-inclusion-proof verific…
woodruffw 57d93e2
_verify: fix comment typos, reflow comments
woodruffw 5986ade
Apply suggestions from code review
woodruffw 286a5a4
_cli: lint
woodruffw b851afe
rekor/client: fix capitalization on Payload key
woodruffw 081caad
rekor/client: fix keys
woodruffw 34a1e4a
_cli: --rekor-bundle implies --rekor-offline
woodruffw caafd8d
sigstore, test: create and use a separate RekorBundle model
woodruffw 0b0d036
sigstore, test: add offline bundle generation
woodruffw 3abef33
sigstore: blacken
woodruffw 8873b75
test: add an offline rekor test
woodruffw d689c03
_cli: tweak `--rekor-offline` language slightly
woodruffw 64f4354
README: update `--help` blocks
woodruffw 76b7f4c
test: unused import
woodruffw 64370f5
sigstore: test Rekor entry's consistency against signing artifacts
woodruffw 96bec0f
conftest: strip trailing whitespace from cert and sig
woodruffw 76e2700
treewide: use .rekor for offline rekor bundle files
woodruffw df005fe
_verify: lint fixes
woodruffw b5eb560
_verify: more lint fixes
woodruffw 1c3788c
README, _cli: `--rekor-offline` -> `--require-rekor-offline`
woodruffw 44f6546
Apply suggestions from code review
woodruffw d1a8157
_verify: clarify comments, add a long comment explaining process
woodruffw e30dd3a
_verify: blacken
woodruffw d7c7d8e
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw 4c2d4a9
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw 592ec32
Merge branch 'main' into ww/offline-rekor-bundle-verification
woodruffw ea45d3e
_cli: add warnings when `--rekor-bundle` is used
woodruffw File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.