ci(release): sign every OCI artifact as sigstore bundle referrers #282
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!282
Loading…
Reference in a new issue
No description provided.
Delete branch "ci/cosign-bundle-referrers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
The image job pinned cosign v2 so podman could read the legacy
sha256-<digest>.sigtags. The module and manifests jobs already ran v3. One pipeline had two signature layouts, and the image one rode an end-of-life major.What
cosign signwrites a sigstore bundle as an OCI referrer of the signed manifest. Forgejo has no referrers API, so the bundle sits behind the OCI 1.1 fallback tagsha256-<digest>. The image job keeps--recursive, so the index and each platform manifest get a bundle..gitea/cosign-signing-config.json) names no Rekor, TSA, CA or OIDC service. Everysignandsign-blobpasses it. This replaces the deprecated--tlog-upload=falseand--use-signing-config=falseflags. Without it, v3 uploads to the public Rekor even with--use-signing-config=false(checked: the bundle carriedtlogEntries).deploy/flux/README.mdandAGENTS.mddescribe the layout and the verify commands.Verified
Against registry:2.8 (no referrers API, same as Forgejo 16.0.2) with cosign 3.1.3:
sha256-<digest>tags with artifactTypeapplication/vnd.dev.sigstore.bundle.v0.3+jsonand the subject set. No.sigtags.cosign verify --key cosign.pub --insecure-ignore-tlog=truepasses for the index and for a platform manifest.tlogEntries.Deliberate gaps
sigstoreSignedreads only the legacy tags and cannot verify the image. Nothing in this repo deploys through podman.timoni mod pull --verify=cosignnever passes--insecure-ignore-tlog, so it already rejected the tlog-less signatures. The README now says to verify with cosign, then pull.🤖 Generated with Claude Code
https://claude.ai/code/session_01XwaXghCjPCVKWTbxCMCBop
Test report
Coverage: 27.0%
Updated by the check workflow · commit
a34387776fView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.