Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Transparent verification of in-toto metadata #38

Open
radu-matei opened this issue Oct 22, 2019 · 0 comments
Open

Transparent verification of in-toto metadata #38

radu-matei opened this issue Oct 22, 2019 · 0 comments
Assignees

Comments

@radu-matei
Copy link
Member

ref cnabio/cnab-spec#288 (comment)

Right now, in order to perform the in-toto validations and verifications, the user must explicitly pass the --in-toto flag.

As @trishankatdatadog suggested, we should just check for the existence of the in-toto metadata and automatically perform the verifications.

If additional target files are passed as flags, they are also used in the verification process.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant