Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Code signing #64

Open
krol3 opened this issue Jul 13, 2022 · 2 comments
Open

Code signing #64

krol3 opened this issue Jul 13, 2022 · 2 comments

Comments

@krol3
Copy link

krol3 commented Jul 13, 2022

Does chain-bench recognize code signing tools like sigstore (cosign, fulcio, rekor)?

@morwn
Copy link
Collaborator

morwn commented Jul 14, 2022

Hi @krol3,
Thank you for your feedback
Chain-bench can easily implement a pipeline instructor for signing 2.4.1:
image

we already implement a parser for the pipeline steps and have shared functionality to validate against a few actions as you can see here

We welcome and loved to get this contribution,
Let me know if you wish to push it

Mor

@krol3
Copy link
Author

krol3 commented Nov 10, 2022

@morwn yeah! I would like to push it! added this validation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants