Skip to content

docs: scope keyless-only inputs and correct KMS backend support - #128

Open
ronens88 wants to merge 1 commit into
mainfrom
docs/timestamp-keyless-scope
Open

ronens88 wants to merge 1 commit into
mainfrom
docs/timestamp-keyless-scope

Conversation

@ronens88

Copy link
Copy Markdown
Contributor

Documentation only. Companion to CycodeLabs/cycodelabs.github.io#123.

Keyless-only inputs

include-timestamp and timestamp-server-url are forwarded to the CLI only inside the keyless branch, and the CLI itself applies timestamping only in keyless mode. The README inputs table and the action.yml descriptions presented these as generally applicable, and the air-gapped section recommending sign-key sits immediately above that table, so the combination read as supported.

  • Marked tlog-upload, include-timestamp, fulcio-server-url, rekor-server-url, timestamp-server-url and allow-submit-data-to-public-sigstore as keyless-only in the README table and the action.yml input descriptions, which render in the Actions UI.
  • Added include-timestamp to the README table; it was previously undocumented.
  • Noted in the air-gapped section that a signature produced with sign-key or a KMS provider carries no timestamp, and that RFC 3161 timestamping for keyed signing is a known gap.

KMS backends

HashiCorp Vault transit is the only implemented --kms provider, so the awskms://<arn> example in the air-gapped section has been removed.

Notes

No behavior change, and no dist rebuild: action.yml is read directly by the Actions runtime and index.js is untouched.

One inconsistency is documented as-is rather than changed, since altering it would be a behavior change: include-timestamp defaults to false in action.yml while the CLI flag defaults to true.

🤖 Generated with Claude Code

The timestamp and transparency-log inputs are forwarded to the CLI only
when `keyless: true`, and the CLI applies them only in keyless mode, but
the README inputs table and the action.yml descriptions presented them
as generally applicable. The air-gapped section recommends `sign-key`
immediately above that table, so the combination read as supported.

- Mark tlog-upload, include-timestamp, fulcio-server-url,
  rekor-server-url, timestamp-server-url and
  allow-submit-data-to-public-sigstore as keyless-only in both the
  README table and the action.yml input descriptions.
- Add the previously undocumented include-timestamp input to the table.
- Note in the air-gapped section that signatures produced with sign-key
  or a KMS provider carry no timestamp.
- Correct the KMS bullet: Vault transit is the only implemented backend,
  so drop the awskms example.

Documentation only. action.yml is read directly by the Actions runtime,
so no dist rebuild is required.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-20T09:17:14.264751Z de81119 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: de81119088

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread attest/README.md
| `fulcio-server-url` | **Keyless only.** Fulcio server URL | `https://fulcio.sigstore.dev` |
| `rekor-server-url` | **Keyless only.** Rekor server URL | `https://rekor.sigstore.dev` |
| `timestamp-server-url` | **Keyless only.** RFC3161 timestamp server URL. Not forwarded to the CLI unless `keyless: true` | — |
| `allow-submit-data-to-public-sigstore` | **Keyless only.** Required when using public Sigstore | `false` |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Mark the consent input as keyless-only in action metadata

This table now correctly identifies allow-submit-data-to-public-sigstore as keyless-only, but its corresponding attest/action.yml description remains unchanged and does not say that the input is ignored otherwise. Since the Actions UI presents action.yml, users configuring the action there can still assume this input affects keyed signing even though attest/index.js only forwards it inside the keyless branch; update that metadata description consistently with the other keyless-only inputs.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant