Skip to content

Support the .sigstore bundle extension #3771

@edgarrmondragon

Description

@edgarrmondragon

Is your feature request related to a problem? Please describe.

The scorecard GH action is detecting that my last 5 releases don't have signed artifacts, though they do have .sigstore bundles.

Describe the solution you'd like

The .sigstore extension should flag a signed artifact.

Describe alternatives you've considered

Can't think of any 😅

Additional context

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions