Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Release 3.3.0
cc @woodruffw
Changelog:
sigstore verify
command now outputs the inner in-toto statementwhen verifying DSSE envelopes. If verification is successful, the output
will be the inner in-toto statement. This allows the user to see the
statement's predicate, which
sigstore-python
does not verify and should beverified by the user.
sigstore attest
subcommand has been added. This command issimilar to
cosign attest
in that it signs over an artifact and apredicate using a DSSE envelope. This commands requires the user to pass
a path to the file containing the predicate, and the predicate type.
Currently only the SLSA Provenance v0.2 and v1.0 types are supported.
sigstore verify
command now supports verifying digests. This meansthat the user can now pass a digest like
sha256:aaaa....
instead of thepath to an artifact, and
sigstore-python
will verify it as if it was theartifact with that digest.