On Thu, Sep 17, 2026 at 08:47:00PM +0200, Rafael Sadowski wrote: > On Thu Aug 20, 2026 at 02:12:01AM +0000, Lucas Raab wrote: > > On Tue, Aug 04, 2026 at 05:15:14PM +0200, Rafael Sadowski wrote: > > > On Tue Aug 04, 2026 at 05:04:46PM +0200, Rafael Sadowski wrote: > > > > OK to import cosign-3.1.2? > > > > > > > > Comment: > > > > sigstore signing tool > > > > > > > > Description: > > > > Signing OCI containers (and other artifacts) using Sigstore. > > > > > > > > Cosign supports: > > > > > > > > - "Keyless signing" with the Sigstore public good Fulcio certificate > > > > authority > > > > and Rekor transparency log (default) > > > > - Hardware and KMS signing > > > > - Signing with a cosign generated encrypted private/public keypair > > > > - Container Signing, Verification and Storage in an OCI registry > > > > - Bring-your-own PKI > > > > > > > > Maintainer: Rafael Sadowski <[email protected]> > > > > > > > > WWW: https://www.sigstore.dev/ > > > > > > > > > > > > > > Now with attachment, submitting new ports does involve this extra task ;) > > > > Warning: cosign-3.1.2 conflicts with xmlrpc-epi-0.54.1p1 > > (net/xmlrpc-epi):/usr/local/bin/sample > > > > Drop bin/sample if it's only intended to be a test file? > > > > OK with bin/cosign only and the others comment out?
yep, ok lraab@
