-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support signing firmware #5
Comments
Ideally this should use https://www.sigstore.dev/ |
@danbev It's a different approach to what I imagined when looking at ORAS, because one of the examples there is that you attach the signatures as a generic 'metadata' associated with the container image, instead of within the artifact itself. Bundling it as you suggest is an interesting approach as well, maybe we need to think about the pros/cons of each of those and decide if we support both or one of them, or maybe even a combination? |
@lulf Thanks for the feedback! I'll take a closer look at the ORAS example today 👍 |
@lulf I've taken a look at using attachments and the issue I ran into previously was fixed with the latest update of oras (details are in the section linked). Is that what you hand in mind with regards to attachments? |
@danbev Yes, I think the signature is a 'layer' with a media type and/or signature type. I think the example I looked at was this https://oras.land/cli/6_reference_types/ |
Ah thanks, I'll read through that 👍 |
@lulf I've also added an alternatives section which sums up the alternative I think we have. |
No description provided.
The text was updated successfully, but these errors were encountered: