Merged
Conversation
77a6ee2 to
7802356
Compare
Signed-off-by: Brian DeHamer <bdehamer@github.com>
7802356 to
d8c307e
Compare
| } | ||
|
|
||
| /* istanbul ignore next */ | ||
| if (stats.size > MAX_SUBJECT_CHECKSUM_SIZE_BYTES) { |
Contributor
There was a problem hiding this comment.
Love this check ❤️
| return res.filter(item => item).map(pat => pat.trim()) | ||
| } | ||
|
|
||
| const digestAlgorithm = (digest: string): string => { |
Contributor
There was a problem hiding this comment.
Should we also verify that the digest is of expected format (hex encoded) too, and fail early if not?
Collaborator
Author
There was a problem hiding this comment.
Good idea. Added a check to ensure the digest is a hex string.
Signed-off-by: Brian DeHamer <bdehamer@github.com>
kommendorkapten
approved these changes
Jan 17, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds support for a new
subject-checksumsinput parameter which allows the user to identify the attestation subjects by passing the path of the checksums file.This enables direct integration with tools like goreleaser, jreleaser, and the sha*sum suite of tools which generate a checksums file.