sigstore.dev
1,301 karma · joined June 23, 2014
sigstore.dev
Happy to answer questions!
I'm a maintainer on gitsign and think we can fix it though!
The tty issue on remote VMs is also getting fixed soon!
Disclosure: I work on Sigstore.
To be honest, crev is pretty elegant but I find manual code review like this to be pretty ineffective in stopping attacks.
https://github.com/chainguard-dev/apko http://github.com/distroless
Blog post: https://blog.chainguard.dev/introducing-apko-bringing-distro...
Disclosure: I helped start the Distroless project years ago and now work at Chainguard.
Disclosure: I work at Chainguard.
Docker hasn't been signing official images for the last several years, so turning this on means you'll get the last correctly signed images, which happen to be years out of date.
Funny to see you here. Matt and I haven't given up on this, we're giving a lot of that another try at Chainguard.
I helped start the Scorecards, SLSA, and Sigstore projects, which are all in the OpenSSF.
For some reason people want a formal specification for everything, even when "N/A" is an applicable option here.
I think COSE (which is what the post was actually about) is though: https://datatracker.ietf.org/doc/html/rfc8152
I have no more context than you do either, and was surprised to find that thread on the IETF tracker to begin with.
There are a bunch of vague accusations that I'm trying to profit or rent seek off of one of the specs I did write about. I didn't create and I don't maintain any of those. I also wouldn't trust any crypto designed by myself.
The original context for writing this post was discussions around using JOSE in the context of signing container images [1]. I was against it and preferred something simpler.
Worst case is if a CI system has permissions to deploy to production, which is really common too.
Another common one to watch out for is permissions to publish artifacts. It's very common for a CI system to build and test something like a container image, then for another system to promote that image to production. Even when the CI system can't touch production directly, it can still be used to pivot to more sensitive targets.
Great find and write-up from the teleport team.