Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

git-repo: Add action to validate signing-event PRs #43

Open
jku opened this issue Feb 27, 2023 · 0 comments
Open

git-repo: Add action to validate signing-event PRs #43

jku opened this issue Feb 27, 2023 · 0 comments
Labels

Comments

@jku
Copy link
Owner

jku commented Feb 27, 2023

This should use the same validation code that the signing event uses to produce a check for the PR
Validate that:

  • metadata is valid TUF metadata, correctly signed
  • the repository is historically coherent (version numbers etc)
  • metadata follows the playground rules (approved delegations, contains the custom fields we expect)
  • targets changes and metadata changes match
@jku jku added the git-repo label Mar 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant