Closed priyawadhwa closed 2 years ago
Checked output for the following scenarios:
cosign save
cosign sign
with a keypair
cosign sign
experimental
cosign verify
cosign verify
cosign verify
- experimental
blobs
cosign sign-blob
cosign verify-blob
cosign sign-blob
- experimental
cosign verify-blob
- experimental
COSIGN_EXPERIMENTAL=1 cosign verify-blob README.md --signature MEUCIQC4b3H8ONOdW2GWH3eHq+WCblbnQx/F/BSgDU5gWhA8+QIgcZryjj8xFcMyIeMpUbc7vW/NNsB96PHIxq2Se3WCj1A=
tlog entry verified with uuid: "29c831359845b333a015136e19613ef5e5c741fb88f8dc9cf207cd772efeee38" index: 1764952
Verified OK
attestations
cosign verify-attestation
cosign attest
- experimental
cosign verify-attestation
- experimental
cosign tree
cosign initialize
other commands
cosign save
and cosign load
have no output.cosign download sbom/attestation/signature
print out json output as expectedcosign triangulate
prints out the sig image as expectedTODOs:
cosign clean
should probably prompt the user before deleting everything
Let's make sure output is accurate and informative for GA