Skip to content

use valid entry with Rekor mock in non-strict mode #481

use valid entry with Rekor mock in non-strict mode

use valid entry with Rekor mock in non-strict mode #481

name: Backward compatibility
on:
workflow_dispatch:
push:
branches: ['main']
pull_request:
branches: ['main']
permissions:
contents: read
jobs:
verify:
name: Verify bundles
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Checkout source
uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v3
- name: Setup node
uses: actions/setup-node@5e21ff4d9bc1a8cf6de233a3057d20ec6b3fb69d # v3
with:
node-version: 16
cache: npm
- name: Install CLI
run: npm install -g @sigstore/cli
- name: Verify bundles
run: |
for FILE in ./tests/bundles/*.sigstore; do
echo "Verifying ${FILE}"
sigstore verify $FILE
done