Skip to content

Intended usage of rekor #2528

@arewm

Description

@arewm

Question

I have recently talked with multiple maintainers of Sigstore about uses of Rekor, but I was wondering if it would be possible to provide concrete guidance on pattern/anti-pattern uses.

One potential use case that I have brought up is searching for available attestations for an artifact. We had wanted to be able to query Rekor for all attestations, but Rekor doesn't guarantee completeness of responses. Therefore, this is presumably an anti-pattern. Can we provide more rationale behind this?

What are the anticipated use cases for Rekor? Is it more intended to provide an existence proof? If I have an attestation, I can look it up in Rekor to see if it exists, its timestamp, etc?

Metadata

Metadata

Labels

questionFurther information is requested

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions