Skip to content

CLI: Verification should support complex policies via a policy file input #629

@woodruffw

Description

@woodruffw

This issue has a few blockers, including coordination with the broader Sigstore community on a machine-readable policy format.

Key components:

  • The sigstore verify subcommands should take a --policy <FILE> or similar option, which would read in the policy file to use during verification.
  • ...or there would be a separate sigstore verify policy subcommand, since sigstore verify identity and sigstore verify github already imply basic policies.

CC @di for visibility.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions