Sascha Grunert
Sascha Grunert
Hey folks, just checking in to see if we can get the binaries :)
https://github.com/hyperium/h2/pull/487 is still unresolved and I personally think that's an issue. If using TCP is an alternative then gRPC seems more mature than Cap’n Proto. We still made good results...
> we could randomize the `repo-path` flag, which is not going to fix the issue, but is considered a good enough mitigation. With that we break one beneficial use case:...
@xmudrii that would be great and I think it will work pretty well!
Yeah, this needs to be changed in rekor / cosign. Probably a bump to cosign v2 may already fix that problem.
Created https://github.com/sigstore/rekor/issues/2342 to discuss that issue on the rekor side.
@dependabot rebase
@dependabot rebase