notaryproject / notation

A CLI tool to sign and verify artifacts
https://notaryproject.dev/
Apache License 2.0
355 stars 84 forks source link

CLI Cmds for Trust Policy Management #769

Open iamsamirzon opened 3 years ago

iamsamirzon commented 3 years ago

As a user, I want to configure trust policy using the notation cli so that I can authenticate signed artifacts.

Summary Intended Outcome The implementation matches with the specification. Additional context Will be revised based on spec updates in each alpha release. The first alpha release will have a baseline implementation that will continue to get revised until we get to release candidate

iamsamirzon commented 2 years ago

Moving this story to discuss milestone.

yizha1 commented 2 years ago

@vaninrao10 I remember the decision is that Trust policy CLI is not in RC-1, but Trust store CLI is in RC-1 scope. @dtzar

dtzar commented 2 years ago

Discussed on community call with Vani - this should be in RC-2.

iamsamirzon commented 1 year ago

Based on the agreement in NV2 community call on 12/5/2022, moving this out of RC-2

yizha1 commented 1 year ago

@iamsamirzon the CLI implementation is not in rc-2 scope, but the spec is in rc.2 scope, can we create an issue for spec only? cc: @vaninrao10

iamsamirzon commented 1 year ago

Discussed in NV2 call on 12/8/2022 to bring in the CLI spec part for Notation Trust Policy

iamsamirzon commented 1 year ago

@iamsamirzon the CLI implementation is not in rc-2 scope, but the spec is in rc.2 scope, can we create an issue for spec only? cc: @vaninrao10

Made this the spec only part

yizha1 commented 1 year ago

@iamsamirzon @vaninrao10 I would suggest creating a new one for implementation, and updating the title of this one by adding key word spec.