#2179 Introduced OCIRepository.status.sourceVerificationFingerprint for triggering a reconciliation when verification material has changed. This is supported if any of the .spec.verify Secret references are being used, but not when both are unset (keyless cosign with public sigstore infra). The reason is the complexity to implement this. The controller only refreshes the key once every 24h and it's hard to tap into it. Research is needed for this.
#2179 Introduced
OCIRepository.status.sourceVerificationFingerprintfor triggering a reconciliation when verification material has changed. This is supported if any of the.spec.verifySecret references are being used, but not when both are unset (keyless cosign with public sigstore infra). The reason is the complexity to implement this. The controller only refreshes the key once every 24h and it's hard to tap into it. Research is needed for this.