Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove non-GA APIs from experimental sign-blob verification flow #2419

Closed
patflynn opened this issue Nov 7, 2022 · 3 comments · Fixed by #2425
Closed

Remove non-GA APIs from experimental sign-blob verification flow #2419

patflynn opened this issue Nov 7, 2022 · 3 comments · Fixed by #2425
Labels
enhancement New feature or request

Comments

@patflynn
Copy link

patflynn commented Nov 7, 2022

Description

This issue is to ensure we remove the use of /api/v1/index/retrieve from cosign verify-blob flow before we launch this version of the command to stable.

Another option is to get Rekor to commit to supporting the API.

@patflynn patflynn added the enhancement New feature or request label Nov 7, 2022
@asraa
Copy link
Contributor

asraa commented Nov 7, 2022

I think there were some users who were still relying on this flow. I agree, we discussed this at some point during the cosign blob verification outputs. I can put out a quick PR to do that, we should label in release notes HEAVILY.

For e.g. here were users failing when that endpoint broke: #1406

@haydentherapper
Copy link
Contributor

We can remove it for 2.0. But it would be worth understanding what the customer workflows are and if we can support those in other ways

@asraa
Copy link
Contributor

asraa commented Nov 8, 2022

GoReleaser updated docs to pass in the signing cert, at least that is done.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants