You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue has a few blockers, including coordination with the broader Sigstore community on a machine-readable policy format.
Key components:
The sigstore verify subcommands should take a --policy <FILE> or similar option, which would read in the policy file to use during verification.
...or there would be a separate sigstore verify policy subcommand, since sigstore verify identity and sigstore verify github already imply basic policies.
This issue has a few blockers, including coordination with the broader Sigstore community on a machine-readable policy format.
Key components:
sigstore verify
subcommands should take a--policy <FILE>
or similar option, which would read in the policy file to use during verification.sigstore verify policy
subcommand, sincesigstore verify identity
andsigstore verify github
already imply basic policies.CC @di for visibility.
The text was updated successfully, but these errors were encountered: