Skip to content

Support for cosign bundle format #4296

@brandtkeller

Description

@brandtkeller

Is your feature request related to a problem? Please describe.

Investigate and propose supporting the sigstore bundle format for signature composition.

Describe the behavior you'd like

  • Given a package exists
  • When signing that package occurs
  • Then a bundle is created for verification purposes

Describe alternatives you've considered

Continue to stick to the current signature strategy.

Additional context

This should offer more verification opportunities for offline environments.

A Sigstore bundle is everything required to verify a signature on an artifact. This is satisfied by the Verification Material and signature Content.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions