You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I see in cosign and sigstore-rs that there's the ability to verify a sigstore bundle with a public key. Is this something that sigstore-python plans to offer as a feature?
The text was updated successfully, but these errors were encountered:
Supporting "bare" public keys isn't an immediate priority for this client: the Sigstore client specifications around long-term keys (versus identity-based signing) aren't as clear, and this client mostly aims to follow the specs strictly.
I'll keep this open, but there's no immediate timeline (much less design plan) for this.
Description
I see in
cosign
andsigstore-rs
that there's the ability to verify a sigstore bundle with a public key. Is this something thatsigstore-python
plans to offer as a feature?The text was updated successfully, but these errors were encountered: