Skip to content

Support OCIRepository.status.sourceVerificationFingerprint for keyless cosign with public sigstore infra #2180

Description

@matheuscscp

#2179 Introduced OCIRepository.status.sourceVerificationFingerprint for triggering a reconciliation when verification material has changed. This is supported if any of the .spec.verify Secret references are being used, but not when both are unset (keyless cosign with public sigstore infra). The reason is the complexity to implement this. The controller only refreshes the key once every 24h and it's hard to tap into it. Research is needed for this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/ociOCI related issues and pull requestsenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions