Skip to content

fix: verify a fragment's signature before validating beside it - #141

Merged
ExtraToast merged 1 commit into
mainfrom
fix/verify-beside-fragments
Oct 7, 2026
Merged

ExtraToast merged 1 commit into
mainfrom
fix/verify-beside-fragments

Conversation

@ExtraToast

Copy link
Copy Markdown
Contributor

The fragments validate-with-fragments pulls (#139) were read by tag and unverified. They only decide what validation accepts and are never packed, but a fragment pushed by anything other than this workflow could still change that.

  • Pull by digest after verifying. Each one is now resolved to a digest, its keyless signature is verified against this workflow's identity (the same check push.sh reads its own push back with), and only then is it pulled, by that digest.
  • cosign is installed before the step. It is installed once, before the pull, instead of after.

Follows a background security review of #139.

@ExtraToast ExtraToast added type: bug Something is broken or behaving incorrectly. area: deploy homelab-deploy, deploy-v2, manifests, and rollout flow. labels Oct 7, 2026
@ExtraToast
ExtraToast merged commit d303857 into main Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: deploy homelab-deploy, deploy-v2, manifests, and rollout flow. type: bug Something is broken or behaving incorrectly.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant