-
Notifications
You must be signed in to change notification settings - Fork 81
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
root-signing metadata is incompatible with current sigstore-rs #1251
Comments
Do you know if https://github.com/theupdateframework/rust-tuf would be compatible or is maintained more actively? |
IIRC they don't have a CLI so testing would be a bit more work (this specific part of the spec seems to be supported but that doesn't mean much) |
|
the metadata in question is now published |
for the record awslabs/tough has released... but now there is a hairy dependency deadlock that still prevents sigstore-rs from using the new release. |
I believe this has been fixed with the latest sigstore-rs release |
This is something that came up during staging testing: sigstore-rs is not compatible with root-signing-staging, and will not be compatible with root-signing if we proceed with #929 without changes.
I'm filing this so we can decide whether this is a blocker for #929 or not. I would suggest it's not a blocker:
That said, tuf-on-ci could start embedding hashes and lengths if that is really needed.
Related sigstore-rs issue sigstore/sigstore-rs#369
The text was updated successfully, but these errors were encountered: