Conversation

scop

Depends on #5793

@ldezldez self-requested a review May 15, 2025 19:28
@ldezldez added the area: installIssue relates to installation or downloading processlabel May 15, 2025
return 0
fi
checksums=$1
http_download "${tmpdir}/${CHECKSUM_COSIGN_BUNDLE}" "${CHECKSUM_COSIGN_BUNDLE_URL}"
Copy link
Contributor Author

@scop scop May 15, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will fail for releases that don't have hose signed checksum .cosign.bundles. I suppose we should address it somehow, but I'm not sure what would be the best way. Some thoughts:

  • Hardcode some version comparison, don't try it for versions known to not have it? This is somewhat a chore to do in the shell script.
  • Skip verify if downloading the cosign bundle fails due to HTTP 404? Not sure if there's a good way to implement that for wget.

An example of this problem can be seen in the CI failure of this PR.

@CLAassistant

CLA assistant check
All committers have signed the CLA.

@scopscop force-pushed the feat/installer-cosign branch from 279fef9 to 259df9f Compare May 23, 2025 13:50
Sign up for free to join this conversation on . Already have an account? Sign in to comment
area: installIssue relates to installation or downloading process
None yet

Successfully merging this pull request may close these issues.