Revert "Add a notice about verification of keyless signing" #1487
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Reverts #1472
Cosign v1.11 now verifies the certificate chain by default when passing the
--cert
option.sigstore/cosign#2139
The certificate must be generated on the GitHub Actions workflow of the
terraform-linters/tflint
repository, otherwise an error will occur for the malformed certificate. This leaves no room for spoofing the public key in a verification flow using Cosign.The only attack surface is for an attacker to take control of this repository, delete existing releases, and recreate releases, which should be sufficiently difficult compared to traditional attack ways.