Skip to content

Deep-Dive into sigstore stack, go-sigstore and cosign as sigstore ref implementation #995

@morri-son

Description

@morri-son

Description
Gather all information around

  • Sigstore infrastructure stack (especially with regartds to Rekor v1/v2) and potential local setup in CI
  • go-sigstore library
  • How Cosign implements go-sigstore for signing and verification as reference implementation

to be able to start with the sigstore handler implementation.

Also check the existing ADR for the desired state and how to implement the new credential plugin for sigstore OIDC.

Goal
Present the topic to the team.

Timebox: ~ 1 day(s)

Metadata

Metadata

Assignees

Labels

area/ipceiImportant Project of Common European Interest

Type

No fields configured for Spike.

Projects

Status
🍺 Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions