1
0
Fork 0

Revert "bump @sigstore/sign from 2.3.2 to 3.0.0"

This reverts commit c6c5ef6b8e.
pull/1852/head
Aiqiao Yan 2024-10-15 18:47:19 +00:00
parent eb8c672aad
commit 19806ac731
3 changed files with 656 additions and 707 deletions

File diff suppressed because it is too large Load Diff

View File

@ -35,8 +35,8 @@
"url": "https://github.com/actions/toolkit/issues" "url": "https://github.com/actions/toolkit/issues"
}, },
"devDependencies": { "devDependencies": {
"@sigstore/mock": "^0.8.0", "@sigstore/mock": "^0.7.4",
"@sigstore/rekor-types": "^3.0.0", "@sigstore/rekor-types": "^2.0.0",
"@types/jsonwebtoken": "^9.0.6", "@types/jsonwebtoken": "^9.0.6",
"nock": "^13.5.1", "nock": "^13.5.1",
"undici": "^5.28.4" "undici": "^5.28.4"
@ -46,8 +46,8 @@
"@actions/github": "^6.0.0", "@actions/github": "^6.0.0",
"@actions/http-client": "^2.2.3", "@actions/http-client": "^2.2.3",
"@octokit/plugin-retry": "^6.0.1", "@octokit/plugin-retry": "^6.0.1",
"@sigstore/bundle": "^3.0.0", "@sigstore/bundle": "^2.3.2",
"@sigstore/sign": "^3.0.0", "@sigstore/sign": "^2.3.2",
"jose": "^5.2.3" "jose": "^5.2.3"
}, },
"overrides": { "overrides": {

View File

@ -86,6 +86,7 @@ const initBundleBuilder = (opts: SignOptions): BundleBuilder => {
witnesses.push( witnesses.push(
new RekorWitness({ new RekorWitness({
rekorBaseURL: opts.rekorURL, rekorBaseURL: opts.rekorURL,
entryType: 'dsse',
fetchOnConflict: true, fetchOnConflict: true,
timeout, timeout,
retry retry
@ -105,5 +106,5 @@ const initBundleBuilder = (opts: SignOptions): BundleBuilder => {
// Build the bundle with the singleCertificate option which will // Build the bundle with the singleCertificate option which will
// trigger the creation of v0.3 DSSE bundles // trigger the creation of v0.3 DSSE bundles
return new DSSEBundleBuilder({signer, witnesses}) return new DSSEBundleBuilder({signer, witnesses, singleCertificate: true})
} }