Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

verify-blob-attestation: Loosen arg requirements if --check-claims=false #2746

Merged
merged 1 commit into from
Mar 8, 2023

Conversation

wlynch
Copy link
Member

@wlynch wlynch commented Feb 24, 2023

Summary

  1. Update --check-claims documentation to better describe the behavior of the flag.
  2. Modify verify-blob-attestation to not require a blob argument if --check-claims=false. This file is not used if we're not checking claims - it can be set to anything and still pass.

See https://sigstore.slack.com/archives/C01PZKDL4DP/p1677006107531799 for more discussion.

Release Note

  • verify-blob-attestation will now accept 0 arguments if --check-claims=false is set.

Documentation

@wlynch
Copy link
Member Author

wlynch commented Feb 24, 2023

CC @priyawadhwa @asraa

@codecov
Copy link

codecov bot commented Feb 24, 2023

Codecov Report

Merging #2746 (feb6305) into main (79f08c3) will increase coverage by 0.50%.
The diff coverage is 44.44%.

@@            Coverage Diff             @@
##             main    #2746      +/-   ##
==========================================
+ Coverage   29.03%   29.54%   +0.50%     
==========================================
  Files         151      151              
  Lines        9642     9646       +4     
==========================================
+ Hits         2800     2850      +50     
+ Misses       6422     6357      -65     
- Partials      420      439      +19     
Impacted Files Coverage Δ
cmd/cosign/cli/options/verify.go 0.00% <0.00%> (ø)
cmd/cosign/cli/verify.go 0.00% <0.00%> (ø)
cmd/cosign/cli/verify/verify_blob_attestation.go 33.17% <66.66%> (-0.31%) ⬇️
pkg/blob/load.go 72.50% <0.00%> (+5.00%) ⬆️
pkg/oci/layout/index.go 28.57% <0.00%> (+28.57%) ⬆️
pkg/oci/layout/write.go 37.50% <0.00%> (+37.50%) ⬆️
pkg/oci/layout/signatures.go 53.84% <0.00%> (+53.84%) ⬆️

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

1. Update --check-claims documentation to better describe the behavior
   of the flag.
2. Modify verify-blob-attestation to not require a blob argument if
   --check-claims=false. This file is not used if we're not checking
   claims - it can be set to anything and still pass.

Signed-off-by: Billy Lynch <[email protected]>
Copy link
Contributor

@hectorj2f hectorj2f left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@hectorj2f hectorj2f merged commit 2670ed3 into sigstore:main Mar 8, 2023
@github-actions github-actions bot added this to the v1.14.0 milestone Mar 8, 2023
dmitris pushed a commit to dmitris/cosign that referenced this pull request Mar 24, 2023
…lse (sigstore#2746)

1. Update --check-claims documentation to better describe the behavior
   of the flag.
2. Modify verify-blob-attestation to not require a blob argument if
   --check-claims=false. This file is not used if we're not checking
   claims - it can be set to anything and still pass.

Signed-off-by: Billy Lynch <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants