Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow attestation upload for DSSE type similar to the intoto type #1928

Closed
aalsabag opened this issue Dec 21, 2023 · 0 comments · Fixed by sigstore/cosign#3466
Closed

Allow attestation upload for DSSE type similar to the intoto type #1928

aalsabag opened this issue Dec 21, 2023 · 0 comments · Fixed by sigstore/cosign#3466
Labels
enhancement New feature or request

Comments

@aalsabag
Copy link

As discussed in Slack, we would like to have attestations uploaded to our attestation store (s3) similar to how the intoto type behaves. This is all because of the choice of cosign to abandon the upload of the intoto type and only have the dsse type.
This implementation does not break existing functionality so I don't think it requires reversioning of the DSSE type. This also still allows prevention of attestation upload in the public rekor instance.
I've gone ahead and raised a PR, but am open to any suggestions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
1 participant