fix(sign)!: keep the configured instance when selecting a Rekor version - #227
Merged
Merged
Conversation
`SigningConfig::with_rekor_version` overwrote `rekor_url` with `RekorApiVersion::default_url()`, which always points at the public-good production log. `sign_blob --staging --v2` and any custom or TUF-derived configuration therefore uploaded to production Rekor v2. Remove the method and select the requested version from the instance's own signing config via `from_tuf_config_with_rekor_version`, which now takes `Option<RekorApiVersion>` and errors when no matching endpoint exists. BREAKING CHANGE: `SigningConfig::with_rekor_version` is removed; use `SigningConfig::from_tuf_config_with_rekor_version(&tuf, Some(version))`. `from_tuf_config_with_rekor_version` takes `Option<RekorApiVersion>` instead of `Option<u32>`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
The production signing config does not publish a Rekor v2 log yet. The interop job's `sign_blob --v2` only worked because `with_rekor_version` silently substituted the built-in production v2 URL. Add a `--rekor-url` option to the example and pass the log URL visibly in the workflow. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Collaborator
Author
|
Interop failed on the |
baszalmstra
approved these changes
Sep 23, 2026
This was referenced Sep 23, 2026
Merged
jku
pushed a commit
that referenced
this pull request
Sep 23, 2026
…#234) * fix(sign): pass RekorApiVersion in TUF service requirement test #226 and #227 merged independently: the test from #218 still passed `Some(1)` to `from_tuf_config_with_rekor_version`, which now takes `Option<RekorApiVersion>`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> * fix(sign): drop clone of Copy ServiceSelector in test #231 made ServiceSelector Copy, so clippy's clone_on_copy fires on the test added in #226. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> * fix(sign): give the custom-instance test fixture a TSA #218 (restored in #226) requires an eligible TSA endpoint, but the custom signing config added by #227 listed none. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> --------- Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
SigningConfig::with_rekor_version. It replacedrekor_urlwithRekorApiVersion::default_url(), which is always production, sosign_blob --staging --v2and custom instances uploaded tolog2025-1.rekor.sigstore.devfrom_tuf_config_with_rekor_versionnow takesOption<RekorApiVersion>instead ofOption<u32>, picks the endpoint from the instance's own signing config, and errors when there is no endpoint for the requested versionsign_blobselects the v2 endpoint from the TUF signing config it already fetchedThis addresses part of the review comment on #176 about
default_url()helpers. Removing the remaining default-URL helpers is left for the 1.0 API cleanup.Conflict note: #226 also touches
from_tuf_config_with_rekor_version(its tests passSome(1)). Whichever PR merges second needs a small rebase.Validation
cargo clippy -p sigstore-sign -p sigstore-conformance --all-targets --all-features -- -D warningscargo test -p sigstore-sign --all-features(new tests: staging v1/v2 keep staging URLs; a custom instance without v2 errors instead of falling back)Signed-off-by: Wolf Vollprecht w.vollprecht@gmail.com
🤖 Generated with Claude Code