cosign icon indicating copy to clipboard operation
cosign copied to clipboard

Move the transparency log feature out of experimental

Open dlorenc opened this issue 4 years ago • 4 comments

dlorenc avatar Mar 20 '21 01:03 dlorenc

Some things I want to figure out first:

How should this be configured? Opt in vs. opt out?

Proposal: Upload send by default for public images (where we can tell), but opt-in for private images.

How should verification be configured?

Is it a failure to verify if the signature is not present? Should we check by default?

Proposal: Check by default for a public image., but warn if the signature is not present, but still pass. Opt-in check for private images. If the opt-in flag is passed for public or private, fail if the signature is not present.

dlorenc avatar Mar 27 '21 13:03 dlorenc

I think we're close here with offline bundling. We'll still want to be careful about adding entries to the log, but verification can happen if there's a bundle, whether or not we're in experimental.

dlorenc avatar May 01 '21 23:05 dlorenc

@dlorenc is this issue still valid or should we close it out? It was added to the GA plan (unclear as to why), so I wanted to verify before taking it off the plan of record.

trixor avatar Aug 02 '22 03:08 trixor

So this basically means that we will remove the "experimental" env var requirement from cosign once Rekor/Fulcio are stable. Think it makes sense as a GA requirement since GA assumes the services are reliable not experimental.

priyawadhwa avatar Aug 02 '22 15:08 priyawadhwa

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 5 days.

github-actions[bot] avatar Nov 08 '22 02:11 github-actions[bot]

I feel like this is covered between https://github.com/sigstore/cosign/pull/2387 and https://github.com/sigstore/cosign/issues/2376 🤷

znewman01 avatar Nov 08 '22 22:11 znewman01

sgtm, will close!

priyawadhwa avatar Nov 08 '22 22:11 priyawadhwa