Jan Zerebecki

Results 21 issues of Jan Zerebecki

Support optional end-to-end trust / content authentication in addition to transport authentication. Support GnuPG (OpenPGP) signatures on anything that changes sources (build inputs). For some content adding multiple signatures by...

Feature

Like the current "Two-person reviewed" but: Reviews are signed by a personal key and included in the history. The history must be secured by a cryptographic protocol (e.g. chained hash...

spec-change

# This is a Bug Report ## Description Bookmarks from another browser get moved after sync. AFAIK this problem can't be fixed without a change in Firefox. ## Steps to...

type/bug

**Description** Have cosign on the developers machine run the same build, creating a signature locally and then sending the signature to the remote in machine, where it is checked and...

enhancement

**Is your feature request related to a problem? Please describe.** The usual way when I use an iso/qcow/raw image is to obtain a web of trust path to the publisher...

kind/enhancement
area/trust

**cos-toolkit version:** 0.7.4-4-gf80dee22 **CPU architecture, OS, and Version:** not applicable **Describe the bug** The qemu images could be much smaller First gz then xz compression wastes about 300M. **To Reproduce**...

kind/enhancement

This is in the context of the plan that anything level 4 and all source requirements will not be included in 1.0. (The following was moved to an issue from...

spec-change
slsa 3
maybe-1.0

Wiki answers lack the link to its edit history. Example: https://ask.fedoraproject.org/en/question/9111/sticky-what-plugins-do-i-need-to-install-to-watch-movies-and-listen-to-music/?answer=12998#post-id-12998 There is no link to its revisions page: https://ask.fedoraproject.org/en/answers/12998/revisions/ For non-wiki answers the text "answered DATE" has that link.

# Feature Request # Configure a user account based on provider specific information and use it as the user for which to add authorized ssh keys. Azure has a prominent...

kind/enhancement

Set SOURCE_DATE_EPOCH and incorporate rebuild counter / release, so that even for rebuilds with unchanged source but updated build depends the date always increases and no build has the same...