Skip to content

Conversation

aaronlew02
Copy link
Collaborator

Partially addresses #959

Summary

This changes enables artifact validation (i.e., confirmation that the message imprint digest of a timestamp matches the artifact digest sent in the request) in the timestamp verifier.
This change also updates the verifier's tests to include staging URIs for the Sigstore TSA, as timestamping functionality is currently restricted to staging environments.

@aaronlew02 aaronlew02 force-pushed the timestamp-verifier branch from 53e826c to 66b30ed Compare June 2, 2025 19:54
@aaronlew02 aaronlew02 requested a review from loosebazooka June 2, 2025 20:32
Copy link
Member

@loosebazooka loosebazooka left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cool, just some minor style things

@aaronlew02 aaronlew02 force-pushed the timestamp-verifier branch from 66b30ed to ece9538 Compare June 3, 2025 14:58
@aaronlew02 aaronlew02 requested a review from loosebazooka June 3, 2025 15:03
Copy link
Member

@loosebazooka loosebazooka left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, one minor thing

@aaronlew02 aaronlew02 force-pushed the timestamp-verifier branch from ece9538 to fd9d69c Compare June 3, 2025 15:19
@aaronlew02 aaronlew02 requested a review from loosebazooka June 3, 2025 15:21
@aaronlew02 aaronlew02 merged commit 55eb097 into main Jun 3, 2025
31 of 32 checks passed
@aaronlew02 aaronlew02 deleted the timestamp-verifier branch June 3, 2025 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants