Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support signing firmware #5

Open
lulf opened this issue Apr 1, 2022 · 8 comments
Open

Support signing firmware #5

lulf opened this issue Apr 1, 2022 · 8 comments
Assignees

Comments

@lulf
Copy link
Member

lulf commented Apr 1, 2022

No description provided.

@lulf
Copy link
Member Author

lulf commented Sep 22, 2022

Ideally this should use https://www.sigstore.dev/

CC @bobmcwhirter

@danbev danbev self-assigned this Nov 3, 2022
@danbev
Copy link
Member

danbev commented Nov 3, 2022

@lulf I've written some notes for this task with some initial investigation and wondering if you be able to take a look and see if I'm on the right track with this?

@lulf
Copy link
Member Author

lulf commented Nov 3, 2022

@danbev It's a different approach to what I imagined when looking at ORAS, because one of the examples there is that you attach the signatures as a generic 'metadata' associated with the container image, instead of within the artifact itself. Bundling it as you suggest is an interesting approach as well, maybe we need to think about the pros/cons of each of those and decide if we support both or one of them, or maybe even a combination?

@danbev
Copy link
Member

danbev commented Nov 4, 2022

@lulf Thanks for the feedback! I'll take a closer look at the ORAS example today 👍

@danbev
Copy link
Member

danbev commented Nov 18, 2022

@lulf I've taken a look at using attachments and the issue I ran into previously was fixed with the latest update of oras (details are in the section linked). Is that what you hand in mind with regards to attachments?

@lulf
Copy link
Member Author

lulf commented Nov 21, 2022

@danbev Yes, I think the signature is a 'layer' with a media type and/or signature type. I think the example I looked at was this https://oras.land/cli/6_reference_types/

@danbev
Copy link
Member

danbev commented Nov 24, 2022

I think the example I looked at was this https://oras.land/cli/6_reference_types/

Ah thanks, I'll read through that 👍

@danbev
Copy link
Member

danbev commented Nov 24, 2022

@lulf
I've added a section about using references to try to understand how that works.

I've also added an alternatives section which sums up the alternative I think we have.
Do these tasks seem reasonable to you?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants