Skip to content

Conversation

@puerco
Copy link
Collaborator

@puerco puerco commented Jul 30, 2025

This commit fixes the broken tag verification by updating the paths and URIs for the verification IDs to those of the new repos.

This fixes the verification and retrieval of commits using the latest release of sourcetool but would break backwards compatibility with attestations signed with older releases unless...

⚠️ Improtant Note

This commit includes a compatibility hack in e4e1f80 to allow verifying attestations with both the old (this repo) and new (slsa-framework/source-actions) signer identities. This commit should be reverted once all repos are signing with the new workflow.

See this issue for more info: #255

Before updating the local_attest this PR needs to go in to support the identity change.

/cc @TomHennen ^^

puerco added 3 commits July 29, 2025 21:00
This commit fixes the broken tag verification by updating the paths
and URIs for the verification IDs to those of the new repos.

Signed-off-by: Adolfo García Veytia (Puerco) <[email protected]>
Signed-off-by: Adolfo García Veytia (Puerco) <[email protected]>
This commits adds a compatibility hack to support both the old and new
actions repository signer identities while we migrate to the new
source-actions repos.

This commit is inteded to be reverted once all repos have signed their
VSAs using the new identity. For more see:

slsa-framework#255

Signed-off-by: Adolfo García Veytia (Puerco) <[email protected]>
@puerco puerco merged commit 6aca8e1 into slsa-framework:main Jul 30, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant