Shopify / ruby-sigstore

Rubygems sigstore signing plugin
Apache License 2.0
7 stars 6 forks source link

Expose the log entry timestamp in RekordEntry #21

Closed rochlefebvre closed 2 years ago

rochlefebvre commented 3 years ago

GemVerifier and RekordEntry drill right into the body of a log entry, but leave behind some fields, notably the entry UUID and its itegrated timestamp.

The latter is important for certificate chain verification, so we should rework & expose this.