You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The current verifierReports did not include the digest for a signature manifest. If an image has multiple signatures, it will be very hard to know which signature failed verification. It's better to show the digest of every OCI artifact that was verified, so that it can be correlated later for different purposes.
An example of current verifierReports in the Ratify logs:
@yizha1 Can you provide an example scenario where each signature will have a different layer digest? From my testing, I notice that the payload that is signed does not change between various signatures. As a result, the signature digest stays the same. Discussion can be found here: #1381 (comment)
Per discussion in the community meeting, the digest is same across different cosign signatures. But we have unique signature hash in the report. Closing the issue.
What would you like to be added?
The current verifierReports did not include the digest for a signature manifest. If an image has multiple signatures, it will be very hard to know which signature failed verification. It's better to show the digest of every OCI artifact that was verified, so that it can be correlated later for different purposes.
An example of current verifierReports in the Ratify logs:
Anything else you would like to add?
No response
Are you willing to submit PRs to contribute to this feature?
The text was updated successfully, but these errors were encountered: