Skip to content

Conversation

alopez-suse
Copy link
Contributor

The SUSE Application Collection has signatures that do not include a "bundle". This means that offline verification of the TLOG (rekor) entry (which is our default behavior) is not possible, and so cosign must make a network request to a running rekor instance to verify transparency log claims.

Previously, in this case, no external Rekor URL was being provided, and this was causing this type of verification to break.

This PR also adds a make test command that verifies real examples of "verification configs" that get sent to the sigstore-interface by the controller and scanner.

@williamlin-suse williamlin-suse merged commit 96da052 into neuvector:main Aug 23, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants