Skip to content

refactor(types)!: deserialize semantic bundle values eagerly - #196

Merged
jku merged 2 commits into
sigstore:mainfrom
wolfv:refactor/semantic-types-main
Sep 1, 2026
Merged

jku merged 2 commits into
sigstore:mainfrom
wolfv:refactor/semantic-types-main

Conversation

@wolfv

@wolfv wolfv commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator

Summary

Recreates #193 and #195 against main. Both were merged into the temporary stack/rekor-v2-write-path branch, so neither change reached main.

  • deserialize bundle media types and supported Rekor kind/version pairs as enums
  • parse checkpoints once while retaining their exact signed envelope bytes
  • deserialize Rekor v1 proof hashes into fixed-size SHA-256 values
  • represent in-toto SHA-256 and SHA-512 subject digests as fixed-size types
  • include the Rekor review follow-ups from refactor: address Rekor review follow-ups #195

This branch is based directly on main and reproduces the final tree delta from those two PRs without replaying the old stack history.

BREAKING CHANGE: bundle media types, Rekor kind/version pairs, checkpoints, proof hashes, and in-toto subject digests now use semantic types.

Testing

  • cargo fmt --all -- --check
  • cargo test --workspace --all-features --quiet
  • git diff --check origin/main..HEAD

wolfv added 2 commits August 28, 2026 14:04
Reject unsupported media types and Rekor entry formats while parsing, parse checkpoints once while retaining their signed text, type Rekor v1 proof hashes, and represent in-toto SHA-256/SHA-512 digests with fixed-size values.

BREAKING CHANGE: bundle media types, Rekor kind/version pairs, checkpoints, proof hashes, and in-toto subject digests now use semantic types.

Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@jku
jku merged commit 0269c9a into sigstore:main Sep 1, 2026
17 checks passed
@wolfv wolfv mentioned this pull request Aug 27, 2026
@wolfv wolfv mentioned this pull request Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants