Skip to content
This repository was archived by the owner on Jan 6, 2026. It is now read-only.

Add support for verifying attestations#8

Open
ChaosInTheCRD wants to merge 11 commits intosigstore:mainfrom
ribbybibby:verify-attestations
Open

Add support for verifying attestations#8
ChaosInTheCRD wants to merge 11 commits intosigstore:mainfrom
ribbybibby:verify-attestations

Conversation

@ChaosInTheCRD
Copy link
Copy Markdown

Adding support to verify attestations for an image.

Based on #6 so must be merged after.

ribbybibby and others added 4 commits January 11, 2022 16:06
Different images will require different verification options. This
commit adds configuration that allows you to define different
'verifiers' for specific image references, or image reference patterns.

At the moment it supports verification by public key, or the existing
options, but should be expanded to include all supported options.

Also modifies the response from the provider to include an error
per-image checked, rather than returning any error as a 'system' error.

I've also removed the _invalid suffix from the key returned in the
response when there's an error. The presence of the 'error' field
indicates this better, I think.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
An image can have multiple signatures and therefore in some cases you'll
want multiple verifiers for the same images.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Comment thread provider.go
var pm map[string]interface{}
json.Unmarshal(p, &pm)

payload := strings.Trim(fmt.Sprintf("%v", pm["payload"]), "\"")
Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not very happy with this line. It seemed that when I got the payload on line 213, I still needed to get the payload field within it and remove the " fields around the base64 encoded value.

@ribbybibby @developer-guy @dlorenc feel free to input if you have any ideas

ribbybibby and others added 6 commits January 13, 2022 09:28
Modify the configuration so that multiple verifiers can be associated
directly with an image reference/pattern. Images will only be verified
for the first pattern they match.

This makes it possible to provide multiple verification options for a
specific image pattern/reference but also fall through to a less-specific
pattern (with different verification options) for images that don't
match a more specific pattern.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Checking the count of errors is enough.

Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Rob Best <robertbest89@gmail.com>
Signed-off-by: Tom Meadows <thomas.meadows@jetstack.io>
@cpanato
Copy link
Copy Markdown
Member

cpanato commented Feb 14, 2023

@ChaosInTheCRD @Dentrax @developer-guy is this still relevant? if yes can we rebase and do a new batch of review? otherwise let's close

@anderssonw
Copy link
Copy Markdown

@ChaosInTheCRD bump! We would very much like to be able to verify attestations as well

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants