Enable fetching signatures without remote get. #4047
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
When using cosign as a dependency and attempting to fetch signatures for a specific signed entity, the signed entity is always fetched from the registry.
In case the signed entity has been fetched previously, it'd be nice to introduce a function similar to the
FetchAttestations
that allows to fetch signatures from the signed entity directly, without reaching out to the registry to fetch the signed entity beforehand.With the current changes in the PR, the error will now not include the reference anymore. However, the changes were also made to
FetchAttestations
in the same way.If we want to include this information, we may wrap the returned error from
FetchAttestations
/FetchSignatures
with the reference, so the content of the error will stay the same.Release Note
NONE
Refs: