Open MinerYang opened 7 months ago
I'm not following your question, can you please clarify?
Hi @bobcallaway ,
What I wondering is including all the signature layers in the new signature manifest when I sign a image using --registry-referrers-mode oci-1-1
If I sign a image, what we expected for the layer of signature manifest is this signature itself.
However, signing by this experimental mode would including all the old signatures that referenced to this image. e.g. there are 3 descriptors in the above manifest layers.
Hi @bobcallaway ,
Any updated here?
I cannot reproduce it. I have created an image with two layers and the manifest of the referrer providing the signature does not list them.
@jonjohnsonjr @hectorj2f any thoughts here?
Question step 1 sign image with regular cosign step2 sign image with COSIGN_EXPERIMENTAL=1 and --registry-referrers-mode oci-1-1 step3 get new signature manifest, will including all preceding signatures layers