Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

keyless: Disable by default. #10

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

sfox-equinix
Copy link

Keyless signing exposes information to the Chainguard-hosted Sigstore infrastructure. The previous default behavior made it possible to accidentally sign an artifact using the public Sigstore infrastructure.

Now, users must explicitly opt-in to keyless signing. This also protects against misconfigured CI systems that would ordinarily use a private Sigstore instance for keyless signing.

Keyless signing exposes information to the Chainguard-hosted
Sigstore infrastructure. The previous default behavior made
it possible to accidentally sign an artifact using the public
Sigstore infrastructure.

Now, users must explicitly opt-in to keyless signing. This also
protects against misconfigured CI systems that would ordinarily
use a private Sigstore instance for keyless signing.
@vipulagarwal
Copy link

vipulagarwal commented Jul 2, 2024

Bringing the discussion on default behavior change here
#9 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants