sigstore-website
sigstore-website copied to clipboard
Small issue on the diagram?
On the diagram on the "How it works" page, it looks to me that an arrow is missing.
Shouldn't there be an arrow between "developers" and "rekor transparency log" ?
Otherwise, it looks like the actual signature is never put in the log. Yet, further to the right of the diagram, "end users" can query rekor for this signature.
Both the fulcio-provided signing cert and the actual signature made from the throw-away signing keys are put in rekor, right?
Agreed, this looks like Fulcio writes directly to Rekor, which is not accurate.
@lukehinds @bobcallaway Do you know this image was generated so we can edit it?