Skip to content

failed to download 10.root.json- while using slsa-verifier within enterprise network? #837

Open
@sohgaura

Description

@sohgaura

Hi Team,

We are trying to use slsa-verifier within enterprise for validating the artifacts. As enterprise network doesn't allow connection to https://tuf-repo-cdn.sigstore.dev/10.root.json , Is it possible to download this file and keep it somewhere local sothat it can work without trying to reach outside enterprise network. Will we see any other limitation like trying to reach to public rekor instance for validation of transaction logs?
How can we use it within an enterprise network which doesn't allow access to public internet?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions