Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OSDOCS#11885: Sigstore signature RN #81997

Merged
merged 1 commit into from
Sep 23, 2024

Conversation

skopacz1
Copy link
Contributor

@skopacz1 skopacz1 commented Sep 17, 2024

OSDOCS-11885

Version(s): 4.17

This PR adds a release note about Sigstore image verification for core cluster images.

QE review:

  • QE has approved this change.

Preview: https://81997--ocpdocs-pr.netlify.app/openshift-enterprise/latest/release_notes/ocp-4-17-release-notes.html#ocp-17-sigstore-verification_release-notes

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Sep 17, 2024
@openshift-ci-robot
Copy link

openshift-ci-robot commented Sep 17, 2024

@skopacz1: This pull request references OSDOCS-11885 which is a valid jira issue.

In response to this:

OSDOCS-11885

Version(s): 4.17

This PR adds a release note about Sigstore image verification for core cluster images.

QE review:

  • QE has approved this change.

Preview:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Sep 17, 2024
@ocpdocs-previewbot
Copy link

ocpdocs-previewbot commented Sep 17, 2024

🤖 Mon Sep 23 16:56:32 - Prow CI generated the docs preview:

https://81997--ocpdocs-pr.netlify.app/openshift-enterprise/latest/release_notes/ocp-4-17-release-notes.html

@skopacz1 skopacz1 changed the title OSDOCS-11885: Sigstore signature RN OSDOCS#11885: Sigstore signature RN Sep 18, 2024
@openshift-ci-robot openshift-ci-robot removed the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Sep 18, 2024
@openshift-ci-robot
Copy link

@skopacz1: No Jira issue is referenced in the title of this pull request.
To reference a jira issue, add 'XYZ-NNN:' to the title of this pull request and request another refresh with /jira refresh.

In response to this:

OSDOCS-11885

Version(s): 4.17

This PR adds a release note about Sigstore image verification for core cluster images.

QE review:

  • QE has approved this change.

Preview:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@skopacz1
Copy link
Contributor Author

@dis016 and @lyman9966 could you PTAL when you have a chance? Thanks!

@lyman9966
Copy link

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Sep 23, 2024
@skopacz1 skopacz1 added this to the Planned for 4.17 GA milestone Sep 23, 2024
@skopacz1 skopacz1 added the peer-review-needed Signifies that the peer review team needs to review this PR label Sep 23, 2024
@adellape adellape self-assigned this Sep 23, 2024
@adellape adellape added the peer-review-in-progress Signifies that the peer review team is reviewing this PR label Sep 23, 2024
[id="ocp-17-sigstore-verification_{context}"]
==== Sigstore signature image verification

With this release, Technology Preview clusters use Sigstore signatures to verify images that were retrieved using a pull spec that references `quay.io/openshift-release-dev/ocp-release`.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit that you could take/leave:

Suggested change
With this release, Technology Preview clusters use Sigstore signatures to verify images that were retrieved using a pull spec that references `quay.io/openshift-release-dev/ocp-release`.
With this release, Technology Preview clusters use Sigstore signatures to verify images that were retrieved using a pull spec that references the `quay.io/openshift-release-dev/ocp-release` image.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I spoke with @wking and I'll implement the spirit of this feedback, however "the quay.io/openshift-release-dev/ocp-release repository" would be more technically accurate here.

@adellape adellape added peer-review-done Signifies that the peer review team has reviewed this PR and removed peer-review-in-progress Signifies that the peer review team is reviewing this PR peer-review-needed Signifies that the peer review team needs to review this PR labels Sep 23, 2024
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Sep 23, 2024
Copy link

openshift-ci bot commented Sep 23, 2024

New changes are detected. LGTM label has been removed.

Copy link

openshift-ci bot commented Sep 23, 2024

@skopacz1: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@skopacz1 skopacz1 merged commit 88d193e into openshift:enterprise-4.17 Sep 23, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
branch/enterprise-4.17 peer-review-done Signifies that the peer review team has reviewed this PR size/S Denotes a PR that changes 10-29 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants