Skip to content
This repository was archived by the owner on Jun 3, 2025. It is now read-only.

Start keyless signing kaniko releases#1841

Merged
imjasonh merged 1 commit intoGoogleContainerTools:masterfrom
mattmoor:keyless-signing
Dec 18, 2021
Merged

Start keyless signing kaniko releases#1841
imjasonh merged 1 commit intoGoogleContainerTools:masterfrom
mattmoor:keyless-signing

Conversation

@mattmoor
Copy link
Copy Markdown
Contributor

@mattmoor mattmoor commented Dec 16, 2021

WIP until #1840 merges.

Submitter Checklist

These are the criteria that every PR should meet, please check them off as you
review them:

  • Includes unit tests
  • Adds integration tests if needed.

See the contribution guide for more details.

Reviewer Notes

  • The code flow looks good.
  • Unit tests and or integration tests added.

Release Notes

kaniko releases are now signed against the public Fulcio root in addition to our documented signing key.

cc @priyawadhwa @dlorenc @imjasonh

Comment on lines 95 to 96
GITHUB_SHA: ${{ github.sha }}
GITHUB_REF: ${{ github.ref }}
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@mattmoor mattmoor changed the title [WIP] Start keyless signing kaniko releases Start keyless signing kaniko releases Dec 17, 2021
@mattmoor
Copy link
Copy Markdown
Contributor Author

cc @imjasonh @priyawadhwa

Rebased this one, I think it's the last one!

@imjasonh imjasonh merged commit c87f8ef into GoogleContainerTools:master Dec 18, 2021
@mattmoor mattmoor deleted the keyless-signing branch December 18, 2021 15:56
gcalmettes pushed a commit to gcalmettes/kaniko that referenced this pull request Dec 24, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants