Skip to content
This repository was archived by the owner on Feb 26, 2024. It is now read-only.

Sign gem#8

Merged
doodzik merged 2 commits into
mainfrom
sign_gem
Oct 29, 2021
Merged

Sign gem#8
doodzik merged 2 commits into
mainfrom
sign_gem

Conversation

@doodzik
Copy link
Copy Markdown

@doodzik doodzik commented Oct 29, 2021

Update gem build --sign to sign the contents of the newly built gem file itself, instead of embedding signatures of the gem's data, metadata, and checksums into the archive. The signature and fulcio cert chain are both included in a single Rekor record entry.

In a follow up PR, we'll refactor that logic into its own class, then call the self-contained bit in gem sign as well.

@doodzik doodzik merged commit 25a4ec2 into main Oct 29, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant