Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal: Deprecate rekor-cli #2290

Open
haydentherapper opened this issue Dec 6, 2024 · 3 comments
Open

Proposal: Deprecate rekor-cli #2290

haydentherapper opened this issue Dec 6, 2024 · 3 comments
Labels
enhancement New feature or request rekor-v2

Comments

@haydentherapper
Copy link
Contributor

Description

rekor-cli provides a command line utility to upload entries to Rekor, search for entries, and verify entries. To reduce the number of tools we maintain in Sigstore, I'd like to deprecate this utility and remove it in Rekor v2. For any functionality that we think should be supported in a CLI tool, I'd rather move it to Cosign as the central Sigstore utility.

For uploading entries to Rekor, a curl command should be sufficient, especially once the number of types is reduced (#2080).

For verifying entries, I'm not sure the use case when someone would like to verify a log entry without also verifying the artifact signature. I'd rather point users to Cosign, and again if the use case does arise, we can add the functionality to Cosign.

@haydentherapper haydentherapper added enhancement New feature or request rekor-v2 labels Dec 6, 2024
@haydentherapper
Copy link
Contributor Author

@lkatalin I know RedHat recommends rekor-cli. Do you have a use case in mind where you need only log entry verification without signature verification, or could Cosign be sufficient?

@lkatalin
Copy link
Contributor

Thanks for the ping @haydentherapper , I'll reach out to our relevant teams about the requirements here.

@lance
Copy link
Contributor

lance commented Dec 10, 2024

@haydentherapper I think we are probably fine with removing this with the 2.0 rekor release. I'm investigating, but at the moment I don't have any great concern. It's one less thing for us to maintain too :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request rekor-v2
Projects
None yet
Development

No branches or pull requests

3 participants