sigstore / root-signing-staging

Staging TUF repository for Sigstore trust root
https://tuf-repo-cdn.sigstage.dev/
Apache License 2.0
3 stars 5 forks source link

New token required #48

Closed jku closed 4 months ago

jku commented 4 months ago

We've made an improvement inTUF-on-CI: in v0.6 signing events will happen in PRs instead of issues. This means the custom token requires an additional permission Pull requests: write.

The new token should be created for @sigstore-bot user and should be stored in repository secrets as TUF_ON_CI_TOKEN. It's ok to replace the existing secret at any time. The old token can be deleted.

Required permissions for sigstore/root-signing-staging are:

Assigning bob as the first approximation.