Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ignore basedir when verifying signatures #6147

Closed
wants to merge 1 commit into from

Conversation

gitu
Copy link
Contributor

@gitu gitu commented Aug 9, 2023

Why the changes in this PR are needed?

The assumtion is that the signature is always verified relative. This is an alternative solution to the problem I tried to solve in #6145.

What are the changes in this PR?

The baseDir is now ignored when verifiying signatures. As per today this has an impact on unpackaged bundles read from directory and bundles fetched from oci.

@ashutosh-narkar
Copy link
Member

Closing as discussed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants