Skip to content
Snippets Groups Projects
  1. Jun 16, 2021
  2. Jun 15, 2021
  3. Jun 07, 2021
  4. Jun 02, 2021
  5. May 29, 2021
  6. May 27, 2021
  7. May 24, 2021
  8. May 14, 2021
  9. May 06, 2021
  10. May 05, 2021
  11. May 01, 2021
  12. Apr 29, 2021
  13. Apr 28, 2021
  14. Apr 21, 2021
  15. Apr 20, 2021
  16. Apr 18, 2021
  17. Apr 16, 2021
  18. Apr 15, 2021
  19. Apr 13, 2021
  20. Apr 12, 2021
  21. Apr 10, 2021
    • Bob Callaway's avatar
      Update rekor REST API to match Trillian semantics (#250) · cce6cabf
      Bob Callaway authored
      
      This patch removes the /api/v1/log/entries/{uuid}/proof endpoint. If you
      have the UUID (aka the leaf Merkle hash), you likely want proof that the
      content represented by that hash is included in the log. There's no need
      for a separate /proof endpoint to deliver the same content.
      
      This commit also ensures that the getLogEntryByIndex and
      getLogEntryByUUID endpoints return an inclusion proof as part of their
      response content. The search endpoint also now returns the inclusion
      proof of all entries returned from the query.
      
      With this patch, Rekor no longer uses the deprecated `GetLeavesByHash`
      Trillian API.
      
      Fixes #229
      
      Signed-off-by: default avatarBob Callaway <bob.callaway@gmail.com>
      cce6cabf
  22. Apr 04, 2021
  23. Mar 27, 2021
  24. Mar 24, 2021
  25. Mar 19, 2021
    • Bob Callaway's avatar
      Remove gzip processing flow completely from rekor (#221) · 8b28f05b
      Bob Callaway authored
      
      * Remove gzip processing flow completely from rekor
      
      Issue #208 reported different handling of gzipped content via fetch vs
      direct upload to rekor server. The code should be consistent, regardless
      of whether content was compressed or not - by always attempting to
      verify the signature against the (unmodified) byte stream.
      
      This patch removes the gzip decoding completely from rekor and verifies
      the bytes supplied or referenced.
      
      Also fixes issue in E2E tests where sending SIGKILL to watch process
      caused message to be printed to stderr, which fails the test when
      running on MacOS.
      
      Fixes #208
      
      Signed-off-by: default avatarBob Callaway <bcallawa@redhat.com>
      8b28f05b
  26. Mar 16, 2021
  27. Mar 14, 2021
  28. Mar 12, 2021
  29. Mar 10, 2021
  30. Mar 03, 2021
    • Bob Callaway's avatar
      Remove API key from path to new log entry (#185) · b0eae9b8
      Bob Callaway authored
      
      Since the API key can be specified as an environment variable and could
      be thought of as an authentication credential, it should not be included
      in the path to the created entry in the log.
      
      Previously we simply appended the new entry's UUID to the full URL,
      which was incorrect if an API key was specified as a query parameter.
      
      Fixes #182
      
      Signed-off-by: default avatarBob Callaway <bcallawa@redhat.com>
      b0eae9b8
    • Bob Callaway's avatar
      no longer require SHA to upload artifacts to log · 4e6156b5
      Bob Callaway authored
      
      Since the verification of a signature will, by definition, include
      verifying the content has not been altered, it is unnecessary to require
      users of the CLI or REST API to specify the SHA256 hash of the content
      when creating a new entry into the log.
      
      Note that the server will still compute the hash and store it in the log
      for ease of comparison.
      
      Fixes #180
      
      Signed-off-by: default avatarBob Callaway <bcallawa@redhat.com>
      4e6156b5
  31. Feb 26, 2021
  32. Feb 25, 2021
  33. Feb 22, 2021
  34. Feb 20, 2021
Loading