refactor: improve cosign signature/attestation lookup with oras#4959
Conversation
Signed-off-by: Wayne Starr <me@racer159.com>
✅ Deploy Preview for zarf-docs canceled.
|
… retrieved) Signed-off-by: Wayne Starr <me@racer159.com>
Codecov Report❌ Patch coverage is
🚀 New features to boost your workflow:
|
brandtkeller
left a comment
There was a problem hiding this comment.
Minor requests otherwise this is neat to see.
Signed-off-by: Wayne Starr <me@racer159.com>
brandtkeller
left a comment
There was a problem hiding this comment.
lgtm. clean and effective - technically a breaking change (public function signature modification) but I believe we're intending to have the policy list utils as not within the boundary.
I haven't seen any requests for this logic to support non-https registries and the current approach is still an improvement over what was here previously. That was the only thing that stood out between pull.go and the implementation here.
AustinAbro321
left a comment
There was a problem hiding this comment.
LGTM, Thanks! I would love for find-images to rely entirely on oras-go instead of Crane. This is a good improvement for now
I am renaming this from chore-> refactor
Description
This improves the speed of cosign signature and attestation lookups using
zarf dev find-imagesto encourage their use.Testing against the Neuvector UDS Package
registry1variant more than halved the totalfind-imagestime:This also aligns the authentication flow of this lookup with that of the image pull on create.
Related Issue
Fixes #N/A
Checklist before merging