GO-2024-3252: gitsign may use incorrect Rekor entries during verification in github.com/sigstore/gitsign
package
Version:
v0.3.1
Opens a new window with list of versions in this module.
Published: Sep 26, 2022
License: Apache-2.0
Opens a new window with license information.
Imports: 24
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
View Source
const (
CommitRef = "refs/attestations/commits"
TreeRef = "refs/attestations/trees"
)
WriteFile writes the given file + a DSSE signed attestation to the corresponding attestation ref.
The SHA of the created commit is returned.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.