rekor: use checkpoint_key_id when available - #1864
Open
ECD5A wants to merge 1 commit into
Open
Conversation
Select Rekor checkpoint verifiers by signed-note name and key ID. Fall back to the first four bytes of log_id for older trust roots. Closes sigstore#1364 Signed-off-by: ECD5A <stelmaknoder@gmail.com>
ECD5A
marked this pull request as ready for review
August 9, 2026 08:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #1364.
Rekor checkpoint verification previously discarded most
TransparencyLogInstancemetadata and selected a verifier using the bundle entry'slog_id. That does not work for trust roots whose signed-note checkpoint key ID differs from the log ID.This change:
TransparencyLogInstancein the trusted keyring;checkpoint_key_id;log_idfor older trust roots withoutcheckpoint_key_id;Validation:
pytest: 197 passed, 30 skipped, 2 xpassedruff check .ruff format --check .mypy sigstorebandit -c pyproject.toml -r sigstoreRelease Note
Used Rekor
checkpoint_key_idvalues when verifying signed checkpoints, with a compatibility fallback for older trust roots.Documentation
No documentation update is required. This corrects internal trusted-root key selection and preserves the existing public API.