Skip to content

Rework sigstore tests - #9005

Closed
williammartin wants to merge 6 commits into
trunkfrom
wm/sigstore-test-rework
Closed

williammartin wants to merge 6 commits into
trunkfrom
wm/sigstore-test-rework

Conversation

@williammartin

Copy link
Copy Markdown
Member

Description

Placeholder PR.

steiza and others added 6 commits April 24, 2024 10:24
The main change is previously we always instantiated a TUF client for
the public good and GitHub Sigstore instances. Now we only instantiate
the TUF client we need, or no client if we are provided a
custom trusted root.

Note that `gh attestation verify` still requires authentication, that is
being addressed in #8995.

Some other changes are coming along for the ride:
- Set TUF cache validity to 1 day, to help serial verification
- Attempt to infer verification policy based on custom trusted root
- Make command output more friendly if you leave off required arguments

Signed-off-by: Zach Steindler <[email protected]>
@williammartin

Copy link
Copy Markdown
Member Author

Commits were pulled into #8997

@Angelface89 Angelface89 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't do these some one else has off my acct pls take the time and inspect all of the stuff made on this site as I didn't even have a guy hub until a few days ago I don't even know how to use it

opts := &Options{}
downloadCmd := &cobra.Command{
Use: "download [<file-path> | oci://<image-uri>] [--owner | --repo]",
Args: cmdutil.MinimumArgs(1, "must specify file path or container image URI, as well as one of --owner or --repo"),

This comment was marked as spam.

opts := &Options{}
downloadCmd := &cobra.Command{
Use: "download [<file-path> | oci://<image-uri>] [--owner | --repo]",
Args: cmdutil.MinimumArgs(1, "must specify file path or container image URI, as well as one of --owner or --repo"),

This comment was marked as spam.

opts := &Options{}
downloadCmd := &cobra.Command{
Use: "download [<file-path> | oci://<image-uri>] [--owner | --repo]",
Args: cmdutil.MinimumArgs(1, "must specify file path or container image URI, as well as one of --owner or --repo"),

This comment was marked as spam.

@Khahan1104

This comment was marked as spam.

@Khahan1104

This comment was marked as spam.

@Khahan1104

This comment was marked as spam.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants