Skip to content

policy: add HTTP source PGP signature verification builtin#3677

Open
tonistiigi wants to merge 1 commit intodocker:masterfrom
tonistiigi:policy-http-pgp
Open

policy: add HTTP source PGP signature verification builtin#3677
tonistiigi wants to merge 1 commit intodocker:masterfrom
tonistiigi:policy-http-pgp

Conversation

@tonistiigi
Copy link
Member

Add verify_http_pgp_signature Rego builtin for HTTP sources using pgpsign with checksum-request/response flow through policy resolution.

@tonistiigi tonistiigi changed the title policy: add HTTP PGP signature verification builtin policy: add HTTP source PGP signature verification builtin Feb 27, 2026
Add verify_http_pgp_signature Rego builtin for HTTP sources using
pgpsign with checksum-request/response flow through policy resolution.
Wire sourcemeta HTTP checksum request/response conversion and add tests.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant