Conversation
The timestamp and transparency-log inputs are forwarded to the CLI only when `keyless: true`, and the CLI applies them only in keyless mode, but the README inputs table and the action.yml descriptions presented them as generally applicable. The air-gapped section recommends `sign-key` immediately above that table, so the combination read as supported. - Mark tlog-upload, include-timestamp, fulcio-server-url, rekor-server-url, timestamp-server-url and allow-submit-data-to-public-sigstore as keyless-only in both the README table and the action.yml input descriptions. - Add the previously undocumented include-timestamp input to the table. - Note in the air-gapped section that signatures produced with sign-key or a KMS provider carry no timestamp. - Correct the KMS bullet: Vault transit is the only implemented backend, so drop the awskms example. Documentation only. action.yml is read directly by the Actions runtime, so no dist rebuild is required. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: de81119088
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| | `fulcio-server-url` | **Keyless only.** Fulcio server URL | `https://fulcio.sigstore.dev` | | ||
| | `rekor-server-url` | **Keyless only.** Rekor server URL | `https://rekor.sigstore.dev` | | ||
| | `timestamp-server-url` | **Keyless only.** RFC3161 timestamp server URL. Not forwarded to the CLI unless `keyless: true` | — | | ||
| | `allow-submit-data-to-public-sigstore` | **Keyless only.** Required when using public Sigstore | `false` | |
There was a problem hiding this comment.
Mark the consent input as keyless-only in action metadata
This table now correctly identifies allow-submit-data-to-public-sigstore as keyless-only, but its corresponding attest/action.yml description remains unchanged and does not say that the input is ignored otherwise. Since the Actions UI presents action.yml, users configuring the action there can still assume this input affects keyed signing even though attest/index.js only forwards it inside the keyless branch; update that metadata description consistently with the other keyless-only inputs.
Useful? React with 👍 / 👎.
Documentation only. Companion to CycodeLabs/cycodelabs.github.io#123.
Keyless-only inputs
include-timestampandtimestamp-server-urlare forwarded to the CLI only inside thekeylessbranch, and the CLI itself applies timestamping only in keyless mode. The README inputs table and theaction.ymldescriptions presented these as generally applicable, and the air-gapped section recommendingsign-keysits immediately above that table, so the combination read as supported.tlog-upload,include-timestamp,fulcio-server-url,rekor-server-url,timestamp-server-urlandallow-submit-data-to-public-sigstoreas keyless-only in the README table and theaction.ymlinput descriptions, which render in the Actions UI.include-timestampto the README table; it was previously undocumented.sign-keyor a KMS provider carries no timestamp, and that RFC 3161 timestamping for keyed signing is a known gap.KMS backends
HashiCorp Vault transit is the only implemented
--kmsprovider, so theawskms://<arn>example in the air-gapped section has been removed.Notes
No behavior change, and no
distrebuild:action.ymlis read directly by the Actions runtime andindex.jsis untouched.One inconsistency is documented as-is rather than changed, since altering it would be a behavior change:
include-timestampdefaults tofalseinaction.ymlwhile the CLI flag defaults totrue.🤖 Generated with Claude Code