Commit Graph

100 Commits

Author SHA1 Message Date
laurentsimon
0cf9e9ce8f Update README.md (#185)
Signed-off-by: laurentsimon <64505099+laurentsimon@users.noreply.github.com>
2022-08-03 20:53:41 -07:00
laurentsimon
caaf1c1b8e feat: Create a verifier as a service (#182)
* update

* update

* update

* tests

* update

* update

* update

* update

* update

* update

* update

* update

* update

* update

* comments

* update

* update

* update

* update

* update
2022-08-03 14:29:25 -07:00
WhiteSource Renovate
8dab07b39b chore(deps): update github/codeql-action action to v2 (#168) 2022-08-03 13:11:28 -05:00
WhiteSource Renovate
cdbab2bf0a fix(deps): update module github.com/google/trillian to v1.4.2 (#176)
Co-authored-by: asraa <asraa@google.com>
2022-08-03 09:27:02 -05:00
WhiteSource Renovate
ab278de311 chore(deps): update github-actions (#175)
Co-authored-by: asraa <asraa@google.com>
2022-08-02 19:28:36 +00:00
WhiteSource Renovate
b911c68206 fix(deps): update module github.com/sigstore/sigstore to v1.3.1 (#177) 2022-08-02 14:19:30 -05:00
WhiteSource Renovate
13f7935ecf fix(deps): update module github.com/sigstore/rekor to v0.10.0 (#178) 2022-08-01 14:06:06 -05:00
Ceridwen Driskill
e2aca61b35 Releases url fix (#172)
Signed-off-by: Ceridwen Driskill <cdriskill@google.com>
2022-07-26 23:19:20 +00:00
WhiteSource Renovate
6dc5a273c7 chore(deps): update github-actions (#165) 2022-07-25 20:31:40 +00:00
laurentsimon
05def419b2 update (#170) 2022-07-25 20:14:00 +00:00
asraa
ad90b50548 release: add notes for release v1.2.0 (#171)
Signed-off-by: Asra Ali <asraa@google.com>
2022-07-25 11:49:49 -07:00
WhiteSource Renovate
fb9aeaf638 fix(deps): update module github.com/sigstore/cosign to v1.10.0 (#166)
Co-authored-by: asraa <asraa@google.com>
v1.2.0
2022-07-25 13:05:03 -05:00
asraa
952915ae4a test: add testing for generic builder multi subject (#162)
* test: add testing for generic builder multi subject

Signed-off-by: Asra Ali <asraa@google.com>

* update comments

Signed-off-by: Asra Ali <asraa@google.com>
2022-07-25 15:50:12 +00:00
WhiteSource Renovate
e154b5534a fix(deps): update module github.com/slsa-framework/slsa-github-generator to v1.2.0 (#167) 2022-07-25 10:12:15 -05:00
asraa
8c4373c533 fix: remove signing certificate output (#160)
* remove signing certificate output

Signed-off-by: Asra Ali <asraa@google.com>
2022-07-22 10:33:48 -05:00
asraa
562cb8410d debug: add error messages for debugging with rekor (#159)
* add error messages for debugging with rekor

Signed-off-by: Asra Ali <asraa@google.com>
2022-07-21 11:50:05 -05:00
asraa
7d53893561 add v1.2.0 generic and go tests (#154)
Signed-off-by: Asra Ali <asraa@google.com>
2022-07-19 15:31:15 -07:00
laurentsimon
6a2f070bf8 feat: Group GHA removatebot updates (#153)
* update

* update
2022-07-18 16:32:46 +00:00
WhiteSource Renovate
058cb80ec1 chore(deps): update ossf/scorecard-action digest to ccd0038 (#151)
Co-authored-by: asraa <asraa@google.com>
2022-07-18 13:16:08 +00:00
WhiteSource Renovate
390d18a96c fix(deps): update module github.com/go-openapi/strfmt to v0.21.3 (#152) 2022-07-18 08:05:26 -05:00
asraa
66533faf78 refactor: refactor packages and create verification options (#129)
Signed-off-by: Asra Ali <asraa@google.com>
2022-07-13 16:52:43 +00:00
Naveen
3b17f9c76f Refactor - deprecated libraries (#128)
- Refactored to move away from github.com/google/trillian/merkle/logverifier"
and github.com/google/trillian/merkle/rfc6962

- Included go mod tidy for validation

- Fixes #https://github.com/slsa-framework/slsa-verifier/issues/61

Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>

Co-authored-by: asraa <asraa@google.com>
2022-07-12 18:57:42 +00:00
asraa
74c0ac257e release: v1.0.1 patch release (#142)
Signed-off-by: Asra Ali <asraa@google.com>
2022-07-12 11:41:57 -05:00
asraa
84f1f38dbf fix: another sharded uuid reference (#143)
* fix: another sharded uuid reference

Signed-off-by: Asra Ali <asraa@google.com>
2022-07-12 10:21:10 -05:00
asraa
0acf40489b fix: properly handle sharded uuids returned from rekor (#141)
Signed-off-by: Asra Ali <asraa@google.com>

Co-authored-by: laurentsimon <64505099+laurentsimon@users.noreply.github.com>
2022-07-11 23:32:24 +00:00
WhiteSource Renovate
567bb6454d chore(deps): update slsa-framework/slsa-github-generator action to v1.1.1 (#121)
Co-authored-by: asraa <asraa@google.com>
2022-07-11 14:55:39 -05:00
WhiteSource Renovate
46cf180c2e chore(deps): update actions/setup-go digest to 84cbf80 (#120)
Co-authored-by: asraa <asraa@google.com>
2022-07-11 18:48:53 +00:00
WhiteSource Renovate
84f7ea1baf chore(deps): update actions/dependency-review-action digest to f187f64 (#119)
Co-authored-by: asraa <asraa@google.com>
2022-07-11 18:34:27 +00:00
WhiteSource Renovate
841a90ee17 chore(deps): update actions/upload-artifact digest to 3cea537 (#134)
Co-authored-by: asraa <asraa@google.com>
2022-07-11 18:07:48 +00:00
WhiteSource Renovate
38278be092 chore(deps): update github/codeql-action digest to ea8fb21 (#135)
Co-authored-by: asraa <asraa@google.com>
2022-07-11 17:42:40 +00:00
WhiteSource Renovate
fcef6ecb5d chore(deps): update ossf/scorecard-action digest to ce330fd (#136)
Co-authored-by: asraa <asraa@google.com>
2022-07-11 17:27:43 +00:00
WhiteSource Renovate
17019c1c07 fix(deps): update module github.com/sigstore/rekor to v0.9.1 (#137) 2022-07-11 12:19:37 -05:00
Naveen
73d10ecfbf Create scorecards.yml (#130) 2022-07-07 17:09:29 -07:00
WhiteSource Renovate
6ac968186d fix(deps): update module github.com/sigstore/sigstore to v1.3.0 (#123)
Co-authored-by: asraa <asraa@google.com>
2022-07-07 12:53:06 +00:00
Naveen
9522708374 Clean up (#125)
- Cleaned up unused function.
- Fixed unnecessary type conversions.
- Fixed some long lines.
- Removed unused variable.

Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
2022-07-07 07:44:39 -05:00
WhiteSource Renovate
8e1e977a89 fix(deps): update module github.com/slsa-framework/slsa-github-generator to v1.1.1 (#124)
Co-authored-by: asraa <asraa@google.com>
2022-07-06 15:57:46 +00:00
WhiteSource Renovate
d972ccaee0 fix(deps): update module github.com/sigstore/rekor to v0.9.0 (#122)
Co-authored-by: asraa <asraa@google.com>
2022-07-06 15:43:58 +00:00
WhiteSource Renovate
83d02990d0 chore(deps): update actions/checkout digest to 2541b12 (#118) 2022-07-06 10:34:55 -05:00
WhiteSource Renovate
257a510230 Configure Renovate (#110)
* chore(deps): add renovate.json

* Update renovate.json

* Delete dependabot.yml

Co-authored-by: laurentsimon <64505099+laurentsimon@users.noreply.github.com>
2022-06-29 21:46:30 +00:00
asraa
588ddc4344 add v1.1.1 hash (#114)
Signed-off-by: Asra Ali <asraa@google.com>
2022-06-29 17:39:18 +00:00
laurentsimon
c06d3f72a9 Iterate thru subjects when verifying subject's hash (#112)
* Iterate thru subjects

* missing file

* update
2022-06-29 17:25:35 +00:00
asraa
f568e1c254 test: fix test returns (#116)
Signed-off-by: Asra Ali <asraa@google.com>
2022-06-29 17:17:16 +00:00
dependabot[bot]
73b3f6a579 🌱 Bump github.com/sigstore/rekor from 0.8.1 to 0.8.2 (#109)
Bumps [github.com/sigstore/rekor](https://github.com/sigstore/rekor) from 0.8.1 to 0.8.2.
- [Release notes](https://github.com/sigstore/rekor/releases)
- [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/rekor/compare/v0.8.1...v0.8.2)

---
updated-dependencies:
- dependency-name: github.com/sigstore/rekor
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-06-28 12:49:48 -05:00
asraa
76a59d8413 tests: update to v1.1.1 testcases (#106)
* update v1.1.1 testcases

Signed-off-by: Asra Ali <asraa@google.com>
v1.1.1
2022-06-21 15:28:02 +00:00
laurentsimon
4405bf51a0 Update RELEASE.md (#107) 2022-06-21 09:51:21 -05:00
asraa
5110b6efc4 update to release 1.1.0 (#104)
Signed-off-by: Asra Ali <asraa@google.com>
2022-06-20 21:35:08 +00:00
asraa
5875b0a74f bump release generator version (#103)
Signed-off-by: Asra Ali <asraa@google.com>
v1.1.0
2022-06-20 21:12:34 +00:00
asraa
3a059ae446 fix: add verification without redis index (#97)
* add verification without redis index

Signed-off-by: Asra Ali <asraa@google.com>
2022-06-20 15:05:20 -05:00
asraa
fbada96c2c chore: update sigstore components (#102)
* update sigstore components

Signed-off-by: Asra Ali <asraa@google.com>
2022-06-20 12:01:58 -05:00
Naveen
40e594d552 Upgrade to go 1.18 (#100)
The https://github.com/slsa-framework/slsa-github-generator is in go
1.18 and keeping it consistent.

Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
2022-06-20 11:32:59 -05:00