constellation/internal/sigstore
Adrian Stobbe b51cc52945
config: sign Azure versions on upload & verify on fetch (#1836)
* add SignContent() + integrate into configAPI

* use static client for upload versions tool; fix staticupload calleeReference bug

* use version to get proper cosign pub key.

* mock fetcher in CLI tests

* only provide config.New constructor with fetcher

Co-authored-by: Otto Bittner <cobittner@posteo.net>
Co-authored-by: Daniel Weiße <66256922+daniel-weisse@users.noreply.github.com>
2023-06-01 13:55:46 +02:00
..
BUILD.bazel config: sign Azure versions on upload & verify on fetch (#1836) 2023-06-01 13:55:46 +02:00
rekor_integration_test.go todo responsibilities and cleanup (#1837) 2023-06-01 12:33:06 +02:00
rekor_test.go Improve measurements verification with Rekor (#206) 2022-10-11 13:57:52 +02:00
rekor.go cli: dynamically select signature validation pubkey for release and pre-release artifacts 2023-05-31 14:00:00 +02:00
sign_test.go config: sign Azure versions on upload & verify on fetch (#1836) 2023-06-01 13:55:46 +02:00
sign.go config: sign Azure versions on upload & verify on fetch (#1836) 2023-06-01 13:55:46 +02:00
sigstore.go dev-docs: Go package docs (#958) 2023-01-19 15:57:50 +01:00
verify_test.go cli: dynamically select signature validation pubkey for release and pre-release artifacts 2023-05-31 14:00:00 +02:00
verify.go cli: dynamically select signature validation pubkey for release and pre-release artifacts 2023-05-31 14:00:00 +02:00