Skip to content

Conversation

@tcnghia
Copy link
Contributor

@tcnghia tcnghia commented Jan 22, 2025

The current logic uses the last .SIGN. file content as signature and verify that against all known keys. This PR fixes the logic to use matching signature to the right verification key.

@tcnghia tcnghia force-pushed the fix-multi-key-support branch 4 times, most recently from 082a65e to ca49d1e Compare January 22, 2025 20:13
Signed-off-by: Nghia Tran <tcnghia@gmail.com>
@tcnghia tcnghia force-pushed the fix-multi-key-support branch from ca49d1e to d39d748 Compare January 22, 2025 20:18
Signed-off-by: Nghia Tran <nghia@chainguard.dev>
@tcnghia tcnghia marked this pull request as ready for review January 22, 2025 22:38
@tcnghia tcnghia force-pushed the fix-multi-key-support branch from 0edcb42 to b8120a8 Compare January 22, 2025 22:40
Signed-off-by: Nghia Tran <nghia@chainguard.dev>
@tcnghia tcnghia force-pushed the fix-multi-key-support branch from b8120a8 to 10822ff Compare January 22, 2025 22:41
Signed-off-by: Nghia Tran <nghia@chainguard.dev>
Signed-off-by: Nghia Tran <nghia@chainguard.dev>
@tcnghia tcnghia changed the title fix multi key support in apko fix multi key support in APKINDEX verification Jan 22, 2025
@tcnghia tcnghia merged commit ec48e30 into main Jan 22, 2025
16 checks passed
@tcnghia tcnghia deleted the fix-multi-key-support branch January 22, 2025 23:02
@xnox
Copy link
Member

xnox commented Jan 22, 2025

@tcnghia thank you!!!!!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants