You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Grype simplifies the installation process through a convenient script. The current script includes a checksum validation step for the binary being installed. Since Grype utilizes cosign to sign the checksum file, it would be beneficial to enhance the installation script by incorporating checksum signature validation.
Why is this needed:
This enhancement ensures consumers can effortlessly verify the installation of binaries, eliminating the need for manual verification.
Additional context:
The text was updated successfully, but these errors were encountered:
Hi @hibare, thank you for the suggestion! I think we would be open to this feature in the install script, especially if it were triggered by a command line flag. We are hesitant to make our installation script rely on a 3rd party program (cosign), but if it were an optional parameter I think that would be fine. Is this something you'd be interested in working on? We'd be happy to help.
wagoodman
changed the title
Installation script: Support automatic checksum signature verification
Installation script: Support checksum signature verification
Jun 6, 2024
What would you like to be added:
Grype simplifies the installation process through a convenient script. The current script includes a checksum validation step for the binary being installed. Since Grype utilizes cosign to sign the checksum file, it would be beneficial to enhance the installation script by incorporating checksum signature validation.
Why is this needed:
This enhancement ensures consumers can effortlessly verify the installation of binaries, eliminating the need for manual verification.
Additional context:
The text was updated successfully, but these errors were encountered: