-
Notifications
You must be signed in to change notification settings - Fork 52
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
make --cert-identity
a required parameter in sigstore verify
#155
Labels
Comments
Since we're trying to maintain parity with |
This is also partially blocked on #108, since |
We are likely going to add this very soon in Cosign. Will tag y'all on the PR for discussion. |
#299 currently contains this change on our side, although I may break it out into a separate PR. |
This is done. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Description
Forgetting to verify who a certificate is actually from is a foot gun, which accidentally caught out urllib3 see urllib3/urllib3#2675
The text was updated successfully, but these errors were encountered: