Skip to content

Conversation

@vszakats
Copy link
Member

@vszakats vszakats commented Oct 10, 2025

The suffix is entirely arbitrary on my part. I could find no mention of
what this should be, and it's also brand new, with no clear practice or
convention I could find.

Anyway, the content of the .sigstore file is the "new bundle" format,
which allows offline verification.

It has been released in full last month by cosign and made the default
in yesterday's release (3.0.1). It's also the officially recommanded
format. This was preceded by a slipped out 3.0.0 release 2 days ago,
triggering a quick fix downstream in curl-for-win.

Ref: curl/curl-for-win@aaf54db

Docs page not yet updated: https://docs.sigstore.dev/about/bundle/
Pending PR: sigstore/docs#385

The suffix is entirely arbitrary on my part. I could find no mention of
what this should be, and it's also brand new, with no clear practice or
convention I could find.

Anyway, the content of the .sigstore file is the "new bundle" format,
which allows offline verification.

It has been released in full last month by cosign and made the default
in yesterday's release (3.0.1). It's also the officially recommanded
format. This was preceded by a slipped out 3.0.0 release 2 days ago,
triggering a quick fix downstream in curl-for-win.

Ref: curl/curl-for-win@aaf54db

Docs page not yet updated: https://docs.sigstore.dev/about/bundle/
Pending PR: sigstore/docs#385

Neither mentions a filename convention.
@vszakats vszakats merged commit ab7c5f1 into curl:master Oct 10, 2025
5 checks passed
@vszakats vszakats deleted the sigstore branch October 10, 2025 00:24
@vszakats
Copy link
Member Author

vszakats commented Oct 10, 2025

.signstore.json was suggested in an example, but

curl-8.16.0_5-win64-mingw.tar.xz.sigstore.json
curl-8.16.0_5-win64-mingw.zip.sigstore.json

just don't look right to me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant