Skip to content

feat(classifier): recognise cosign hardware-key signing touches - #13

Draft
Talgarr wants to merge 3 commits into
mainfrom
add-rule-cosign
Draft

feat(classifier): recognise cosign hardware-key signing touches#13
Talgarr wants to merge 3 commits into
mainfrom
add-rule-cosign

Conversation

@Talgarr

@Talgarr Talgarr commented Jun 23, 2026

Copy link
Copy Markdown
Owner

cosign (Sigstore) can sign with a PIV hardware token (touch-policy=always) via its go-piv / PKCS#11 backend, so a sustained touch-wait while cosign runs is a hardware-key signing request. Classify sign / sign-blob / attest / generate-key-pair subcommands and extract the image ref or blob resource.

Talgarr and others added 3 commits June 25, 2026 12:43
cosign (Sigstore) can sign with a PIV hardware token (touch-policy=always)
via its go-piv / PKCS#11 backend, so a sustained touch-wait while cosign runs
is a hardware-key signing request. Classify sign / sign-blob / attest /
generate-key-pair subcommands and extract the image ref or blob resource.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add an e2e check that signs a scratch blob with `cosign sign-blob` using a
PIV PKCS#11 key (touch-policy=always) supplied via WHENCE_E2E_COSIGN_KEY,
asserting the classifier named `cosign`. Skips when cosign or the key is
absent. Register it in the driver and document it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The cosign e2e test drives `cosign sign-blob`; add it so it lands on
PATH in `nix develop`.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant