Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

sigstore 4.0 upgrade details #383

Copy link
Copy link
@jku

Description

@jku
Issue body actions

Filing as heads up: The sigstore-python 4.0 upgrade is a bit more complicated since there are related service changes. I'll add more details here in next day or two but short story is:

  • sigstore-python 4.0 contains support for rekor v2 transparency log
  • rekor v2 is not yet fully deployed on the public good instance (sigstore.dev) but once it is, sigstore-python 4.0 will start using it (by default) when signing. There is no strict deadline for full deployment but a couple of months is a good guess (the rekor v1 instance will remain usable even after that)
  • verifying signature bundles (that were produced with rekor v2) requires sigstore-python 4.0 (or another sigstore client with rekorv2 support)

sigstore-python 3.6.x series is still maintained so there is no rush to upgrade here

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filePull requests that update a dependency fileenhancementNew feature or requestNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      Morty Proxy This is a proxified and sanitized view of the page, visit original site.