in-toto / witness

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
https://witness.dev
Apache License 2.0
416 stars 60 forks source link

Fixing incorrect error message on Verify #350

Closed ChaosInTheCRD closed 7 months ago

ChaosInTheCRD commented 10 months ago

The changed error message seems to have been copied from cmd/sign.go and is a confusing error to present to the user. Instead it should be specified that the policy file can't be opened.

ChaosInTheCRD commented 10 months ago

just fyi I am currently working on improving how we handle required flags. Maybe we should save the merge until I finish? shouldn't take long.

mikhailswift commented 9 months ago

These changes look good. Can we get the merge conflicts sorted, change Aditya recommended, and lining fixed up so this can get merged?

netlify[bot] commented 8 months ago

Deploy Preview for witness-project canceled.

Name Link
Latest commit 336ad64f1579b3befa62cae3d907415e9b3dc65e
Latest deploy log https://app.netlify.com/sites/witness-project/deploys/66350c4e5c8e810008d25f2b