Skip to content

Conversation

@JeroenKnoops
Copy link
Member

@JeroenKnoops JeroenKnoops commented Nov 18, 2022

EXPERIMENTAL flag is not necessary anymore in Cosign v2.0.0

See also: https://blog.sigstore.dev/cosign-2-0-released/

Current support:

  • private signing (with public tlog) only with cosign Public and Private key.
  • public signing (with public tlog) only in keyless mode.

Support for keyless signing with private Rekor / Fulcio is not supported yet.

@JeroenKnoops JeroenKnoops added dependencies Pull requests that update a dependency file signing labels Nov 18, 2022
@JeroenKnoops
Copy link
Member Author

This is related to #186

EXPERIMENTAL flag is not necessary anymore in Cosign v0.14.0

See also: sigstore/cosign#2457

Signed-off-by: Jeroen Knoops <jeroen.knoops@philips.com>
@JeroenKnoops JeroenKnoops force-pushed the keyless-is-not-experimental branch from 8747dcc to 886c565 Compare March 7, 2023 09:37
…re to use keyless signing with PUBLIC tlog

Signed-off-by: Jeroen Knoops <jeroen.knoops@philips.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file signing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants