Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TUF: Remove support for non-bundled roots of trust #584

Closed
woodruffw opened this issue Mar 25, 2023 · 1 comment · Fixed by #626
Closed

TUF: Remove support for non-bundled roots of trust #584

woodruffw opened this issue Mar 25, 2023 · 1 comment · Fixed by #626
Assignees
Labels
component:tuf TUF related components enhancement New feature or request

Comments

@woodruffw
Copy link
Member

Per conversation in #542: the bundled trust root is now considered the stable interface for retrieving all of the various pieces of Sigstore's root of trust, so we can remove support for the "standalone" targets that it replaced.

We should do #580 first, to convince ourselves that we haven't introduced any bugs by switching over to the bundled trust root.

@woodruffw woodruffw added the enhancement New feature or request label Mar 25, 2023
@asraa
Copy link
Contributor

asraa commented Mar 29, 2023

Hey! Just FYI I've created a staging repository that can be pushed to a new staging bucket (to keep backwards compatibility because the root keys are different) that is now update-able and contains the trusted_root.json

@haydentherapper can fill you in about what the URL of the bucket will be

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
component:tuf TUF related components enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants