David Dworken
c9df6639e8
Upgrade slsa-verifier per https://github.com/slsa-framework/slsa-verifier/issues/285
2022-10-03 14:31:50 -07:00
David Dworken
6db8044bec
Add server tests for redaction
2022-09-21 21:46:46 -07:00
David Dworken
fb401dab88
Resume using the modernc.org sqlite driver so it works with CGO_ENABLED=0
2022-09-21 19:49:24 -07:00
David Dworken
5de6e17920
Bump dependency versions
2022-09-17 12:03:12 -07:00
David Dworken
83a0beff43
Bump go version, remove the vendored slsa library, and depend on a newer copy with a different API. Updates now work.
2022-09-02 00:15:58 -07:00
dependabot[bot]
580bcb0db4
Bump github.com/sigstore/cosign from 1.7.2 to 1.10.1
...
Bumps [github.com/sigstore/cosign](https://github.com/sigstore/cosign ) from 1.7.2 to 1.10.1.
- [Release notes](https://github.com/sigstore/cosign/releases )
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sigstore/cosign/compare/v1.7.2...v1.10.1 )
---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2022-08-10 18:51:08 +00:00
David Dworken
2f8727f29b
A new way of releasing, taking advantage of config-file to avoid having to create a new commit per platform
2022-05-28 00:01:38 -07:00
David Dworken
fb569b86fa
Update dependencies
2022-05-27 22:32:53 -07:00
David Dworken
c79a510b9c
Maybe working xattr support for code signing
2022-04-25 22:03:31 -07:00
David Dworken
89fd59a132
Disabe CGO since it is incompatible with cross-compiling for darwin and swap to a non-cgo sqlite library
2022-04-20 17:28:19 -07:00
David Dworken
3d7af0cd4b
Add SLSA verification of updated binary
...
Currently the SLSA verifier is meant to be used a standalone binary. I copied a bit of code from their main (and imported the rest of their code as a library) in order to support embedding it as a library. This ensures that the updated hishtory passes SLSA L3.
2022-04-16 16:02:07 -07:00
David Dworken
dc6fb6a47b
Refactor tests to make them non-flakey and pass on actions
...
This required adding the ability to have hishtory run synchronously to avoid reconditions. I also added additional waiting code. Also a whole bunch of new tests and disabled gorm's default logger which also caued flakeyness
2022-04-14 20:18:49 -07:00
David Dworken
fb52b98379
Swap generous date parsing to using a library
2022-04-11 23:22:49 -07:00
David Dworken
252e9ab122
Website landing page, install instructions, update command, status command, set up postgres, and fixing broken tests
2022-03-29 21:56:28 -07:00
David Dworken
3d450a1175
in progress integration tests
2022-01-09 11:00:53 -08:00
David Dworken
a523504c40
split into local client and remote client, and add tests
2022-01-08 21:59:28 -08:00
David Dworken
6fbad3a194
init versions pre-split
2022-01-08 20:27:18 -08:00