Conversation
wolfv
force-pushed
the
refactor/deserialize-semantic-types
branch
from
August 19, 2026 09:31
4dbb526 to
eae8d14
Compare
wolfv
force-pushed
the
stack/rekor-v2-write-path
branch
from
August 19, 2026 09:45
4490933 to
e40fc0a
Compare
wolfv
force-pushed
the
refactor/deserialize-semantic-types
branch
from
August 19, 2026 09:45
eae8d14 to
4392f32
Compare
Reject unsupported media types and Rekor entry formats while parsing, parse checkpoints once while retaining their signed text, type Rekor v1 proof hashes, and represent in-toto SHA-256/SHA-512 digests with fixed-size values. BREAKING CHANGE: bundle media types, Rekor kind/version pairs, checkpoints, proof hashes, and in-toto subject digests now use semantic types. Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
wolfv
force-pushed
the
refactor/deserialize-semantic-types
branch
from
August 25, 2026 08:12
4392f32 to
3067877
Compare
jku
approved these changes
Aug 27, 2026
Comment on lines
+503
to
+504
| let sha512 = Sha512Hash::try_from_slice(&sigstore_crypto::sha512(bytes)) | ||
| .expect("SHA-512 produces a 64-byte digest"); |
Member
There was a problem hiding this comment.
I guess if we are changing things we could make sha512 return a Sha512Hash now that it exists -- this would match sha256...
Comment on lines
84
to
85
| /// bundle format with typed fields. This uses raw strings as returned by the | ||
| /// Rekor V1 API (hex-encoded hashes). |
Member
There was a problem hiding this comment.
this looks at least partly misleading now
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #176. This moves validation to deserialization boundaries so downstream code works with semantic values rather than repeatedly parsing wire representations.
The temporary base branch mirrors the exact #176 head so this PR shows only the follow-up diff. Once #176 merges, this PR should be retargeted to
mainand the temporary base deleted.BREAKING CHANGE: bundle media types, Rekor kind/version pairs, checkpoints, proof hashes, and in-toto subject digests now use semantic types.