Skip to content

Make sure cosign release signing takes rekor v2 change into account #4738

@jku

Description

@jku
  • the default signature transparency log (the one recommended by signingconfig) will be rekor v2 in the future New post about signing defaults change sigstore-blog#92
  • cosign 3.x follows this default
  • cosigns own release process should make sure that this is appropriate for cosign releases: cosign < 3.0.5 will not be able to verify signatures with rekor v2 entries (without using additional CLI flags)
  • so possibly cosign releases still want to use rekor v1 for a while to make sure that bootstrapping is not painful

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions