Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OIDC Signing with Github now production ready? #120

Closed
J12934 opened this issue Apr 28, 2023 · 1 comment
Closed

OIDC Signing with Github now production ready? #120

J12934 opened this issue Apr 28, 2023 · 1 comment
Labels
question Further information is requested

Comments

@J12934
Copy link
Contributor

J12934 commented Apr 28, 2023

Question

Hi 👋

The readme here says that OIDC signing from this action is not production ready yet.
The cosign docs page on OIDC signing states that OIDC signing is now not experimental anymore: https://docs.sigstore.dev/cosign/openid_signing/

Identity-based signing is now fully supported in Cosign.

Does this also mean that OIDC based signing from Github Actions is production ready?

Thank you 🙌

@J12934 J12934 added the question Further information is requested label Apr 28, 2023
@cpanato
Copy link
Member

cpanato commented May 16, 2023

yes, we can consider production ready, several projects are using that already :)

thanks, will close this issue

@cpanato cpanato closed this as completed May 16, 2023
J12934 added a commit to iteratec/cosign-installer that referenced this issue May 16, 2023
See comment in sigstore#120

Signed-off-by: Jannik Hollenbach <jannik.hollenbach@iteratec.com>
cpanato pushed a commit that referenced this issue May 17, 2023
See comment in #120

Signed-off-by: Jannik Hollenbach <jannik.hollenbach@iteratec.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants