sigstore / root-signing

TUF repository for Sigstore trust root
Apache License 2.0
80 stars 77 forks source link

Merge ceremony branch ceremony/2024-03-19 into main #1177

Closed sigstore-bot closed 3 months ago

sigstore-bot commented 3 months ago

Merge ceremony branch to main

kommendorkapten commented 3 months ago

With the open PR against awslabs/tough:

kommendorkapten@m1m14:~/git/tough % ./target/debug/tuftool download out --root ~/git/root-signing/repository/repository/5.root.json -t http://localhost:8081/targets -m http://localhost:8081
Downloading targets to "out"
    -> ctfe.pub
    -> fulcio_intermediate_v1.crt.pem
    -> trusted_root.json
    -> fulcio_v1.crt.pem
    -> rekor.pub
    -> fulcio.crt.pem
    -> ctfe_2022.pub
    -> artifact.pub
kommendorkapten@m1m14:~/git/tough %
kommendorkapten commented 3 months ago

With cosign:

kommendorkapten@m1m14:~/git/cosign % ./cosign initialize --root /Users/kommendorkapten/git/root-signing/repository/repository/5.root.json --mirror http://localhost:8081
Root status:
...