Skip to content

docs: update cosign readme.md#14

Merged
binbin-li merged 20 commits intonotaryproject:mainfrom
junczhu:init-cosign-readme
Apr 1, 2025
Merged

docs: update cosign readme.md#14
binbin-li merged 20 commits intonotaryproject:mainfrom
junczhu:init-cosign-readme

Conversation

@junczhu
Copy link
Copy Markdown
Contributor

@junczhu junczhu commented Feb 25, 2025

Adds a comprehensive README file for the ratify-verifier-go Cosign client library.
The key changes include:

  • Overview of Cosign Solution: Provides a brief introduction to the Cosign verifier, explaining key concepts, its purpose and functionality.
  • Verify Scenarios and Usage Instructions: Details on how to integrate and use the Cosign verifier within the Ratify framework.
  • Refences

Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Feb 25, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu junczhu marked this pull request as ready for review February 26, 2025 06:47
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu
Copy link
Copy Markdown
Contributor Author

junczhu commented Feb 26, 2025

Updated PR description.

Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu junczhu marked this pull request as draft February 27, 2025 12:13
@junczhu junczhu marked this pull request as ready for review February 27, 2025 15:26
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
junczhu added 3 commits March 3, 2025 04:31
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu junczhu force-pushed the init-cosign-readme branch 3 times, most recently from 02e9a9d to 956587c Compare March 3, 2025 09:04
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu junczhu force-pushed the init-cosign-readme branch from 956587c to df7921a Compare March 3, 2025 09:25
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces a comprehensive README file that provides an overview, workflows, and detailed usage instructions for the Cosign verifier within the ratify-verifier-go client library.

  • Adds an introductory glossary and conceptual background on Sigstore components.
  • Includes detailed Mermaid diagrams illustrating signing and verification workflows.

@junczhu junczhu force-pushed the init-cosign-readme branch from 75b0391 to 0617f68 Compare March 24, 2025 04:47
@shizhMSFT shizhMSFT requested a review from Copilot March 25, 2025 08:06
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu junczhu force-pushed the init-cosign-readme branch from 0617f68 to 8c6d794 Compare March 25, 2025 10:53
@junczhu junczhu requested a review from Copilot March 28, 2025 04:33
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds a comprehensive README file for the ratify-verifier-go Cosign client library. The documentation provides an overview of the Cosign solution, explains the signing and verification workflows using mermaid diagrams, and details various verification scenarios and concepts.

@junczhu junczhu force-pushed the init-cosign-readme branch from 585aca4 to ca4f3b4 Compare March 28, 2025 04:38
Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@junczhu junczhu force-pushed the init-cosign-readme branch from ca4f3b4 to 93f5ce8 Compare March 28, 2025 04:39
shizhMSFT
shizhMSFT previously approved these changes Mar 28, 2025
Copy link
Copy Markdown

@shizhMSFT shizhMSFT left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM with suggestions

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds a comprehensive README for the Cosign client library used in the Ratify verifier framework, providing background information, detailed workflows for signing and verification (both keyless and key-based), and references.

  • Introduces key concepts and components (Fulcio, Rekor, TUF) with diagrams.
  • Provides sample outputs for both keyless and key-based verification scenarios.
  • Lists detailed external references and notes for future improvements.

@junczhu junczhu force-pushed the init-cosign-readme branch 2 times, most recently from 4c23f10 to 98b777a Compare April 1, 2025 02:19
binbin-li
binbin-li previously approved these changes Apr 1, 2025
Copy link
Copy Markdown
Contributor

@binbin-li binbin-li left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Signed-off-by: Juncheng Zhu <junczhu@microsoft.com>
@binbin-li binbin-li merged commit 6d36381 into notaryproject:main Apr 1, 2025
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants