Jussi Kukkonen

Results 453 comments of Jussi Kukkonen

https://github.com/jku/root-signing/pull/1 contains the workflow enabling/disabling commits that we should include in the initial signing event branch (to disable legacy workflows and enable tuf-on-ci ones)

Collecting items that must be done before initial tuf-on-ci signing event * [ ] Decide/ communicate signing event date (currently looking at week 35-36, we'll make a proposal in next...

marking this closed: the actual migration is in #1320

> I agree to extending both. I think we should try to leave 2 weeks to handle any issues, so I would say 21 days for the root signing period...

IIRC they don't have a CLI so testing would be a bit more work (this specific part of the spec seems to be supported but that doesn't mean much)

* I believe the upstream PR fixing the blocker has been merged in awslabs/tough: https://github.com/awslabs/tough/pull/778 * awslabs/tough release, update in sigstore-rs and a sigstore-rs release would still be needed *...

for the record awslabs/tough has released... but now there is a hairy dependency deadlock that still prevents sigstore-rs from using the new release.

I believe this has been fixed with the latest sigstore-rs release