Skip to content

Please add link to instruction on how consumers verify xxx.sigstore.json #164

Open
@sgpinkus

Description

@sgpinkus

Description

Using this action is simple. But how do you verify the output as a consumer of some software released signed this way. To most users all they see is a big cryptic JSON document with no idea how to verify it. Please add a link or instructions here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions