Skip to content

Commit c0f9a86

Browse files
committed
bump embedded signing configs
1 parent 8228f35 commit c0f9a86

File tree

4 files changed

+28
-20
lines changed

4 files changed

+28
-20
lines changed

sigstore/_internal/trust.py

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -616,13 +616,7 @@ def from_tuf(
616616
sc_path = updater.get_signing_config_path()
617617
inner_sc = trustroot_v1.SigningConfig.from_json(Path(sc_path).read_bytes())
618618
except TUFError as e:
619-
# TUF repo may not have signing config yet: hard code values for prod:
620-
# https://github.com/sigstore/sigstore-python/issues/1388
621-
if url == DEFAULT_TUF_URL:
622-
embedded = read_embedded("signing_config.v0.2.json", url)
623-
inner_sc = trustroot_v1.SigningConfig.from_json(embedded)
624-
else:
625-
raise e
619+
raise e
626620

627621
return cls(
628622
trustroot_v1.ClientTrustConfig(

sigstore/_store/https%3A%2F%2Ftuf-repo-cdn.sigstage.dev/signing_config.v0.2.json

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,8 @@
66
"majorApiVersion": 1,
77
"validFor": {
88
"start": "2022-04-14T21:38:40Z"
9-
}
9+
},
10+
"operator": "sigstore.dev"
1011
}
1112
],
1213
"oidcUrls": [
@@ -15,7 +16,8 @@
1516
"majorApiVersion": 1,
1617
"validFor": {
1718
"start": "2025-04-16T00:00:00Z"
18-
}
19+
},
20+
"operator": "sigstore.dev"
1921
}
2022
],
2123
"rekorTlogUrls": [
@@ -24,7 +26,8 @@
2426
"majorApiVersion": 1,
2527
"validFor": {
2628
"start": "2021-01-12T11:53:27Z"
27-
}
29+
},
30+
"operator": "sigstore.dev"
2831
}
2932
],
3033
"tsaUrls": [
@@ -33,7 +36,8 @@
3336
"majorApiVersion": 1,
3437
"validFor": {
3538
"start": "2025-04-09T00:00:00Z"
36-
}
39+
},
40+
"operator": "sigstore.dev"
3741
}
3842
],
3943
"rekorTlogConfig": {
@@ -42,4 +46,4 @@
4246
"tsaConfig": {
4347
"selector": "ANY"
4448
}
45-
}
49+
}
Lines changed: 17 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,23 @@
11
{
2-
"comment": "Place holder for use until prod actually has a signing config: see ClientTrustConfig.from_tuf()",
32
"mediaType": "application/vnd.dev.sigstore.signingconfig.v0.2+json",
43
"caUrls": [
54
{
65
"url": "https://fulcio.sigstore.dev",
76
"majorApiVersion": 1,
87
"validFor": {
98
"start": "2022-04-13T20:06:15.000Z"
10-
}
9+
},
10+
"operator": "sigstore.dev"
1111
}
1212
],
1313
"oidcUrls": [
1414
{
1515
"url": "https://oauth2.sigstore.dev/auth",
1616
"majorApiVersion": 1,
1717
"validFor": {
18-
"start": "2025-04-30T00:00:00Z"
19-
}
18+
"start": "2022-04-13T20:06:15.000Z"
19+
},
20+
"operator": "sigstore.dev"
2021
}
2122
],
2223
"rekorTlogUrls": [
@@ -25,15 +26,24 @@
2526
"majorApiVersion": 1,
2627
"validFor": {
2728
"start": "2021-01-12T11:53:27.000Z"
28-
}
29+
},
30+
"operator": "sigstore.dev"
2931
}
3032
],
3133
"tsaUrls": [
34+
{
35+
"url": "https://timestamp.sigstore.dev/api/v1/timestamp",
36+
"majorApiVersion": 1,
37+
"validFor": {
38+
"start": "2025-07-04T00:00:00Z"
39+
},
40+
"operator": "sigstore.dev"
41+
}
3242
],
3343
"rekorTlogConfig": {
3444
"selector": "ANY"
3545
},
3646
"tsaConfig": {
37-
"selector": "ALL"
47+
"selector": "ANY"
3848
}
39-
}
49+
}

test/unit/conftest.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -252,7 +252,7 @@ def signer():
252252
trust_config = ClientTrustConfig.staging()
253253
trust_config.signing_config._tlogs.append(
254254
Service(
255-
url="https://log2025-alpha1.rekor.sigstage.dev", major_api_version=2
255+
url="https://log2025-alpha1.rekor.sigstage.dev", major_api_version=2, operator="sigstage.dev"
256256
)
257257
)
258258
return SigningContext.from_trust_config(trust_config)

0 commit comments

Comments
 (0)