Re: NEW: security/cosign

Lucas Raab <[email protected]>
Newsgroups gmane.os.openbsd.ports
Message-ID <[email protected]>
On Tue, Aug 04, 2026 at 05:15:14PM +0200, Rafael Sadowski wrote:
> On Tue Aug 04, 2026 at 05:04:46PM +0200, Rafael Sadowski wrote:
> > OK to import cosign-3.1.2?
> > 
> > Comment:
> > sigstore signing tool
> > 
> > Description:
> > Signing OCI containers (and other artifacts) using Sigstore.
> > 
> > Cosign supports:
> > 
> > - "Keyless signing" with the Sigstore public good Fulcio certificate authority
> >   and Rekor transparency log (default)
> > - Hardware and KMS signing
> > - Signing with a cosign generated encrypted private/public keypair
> > - Container Signing, Verification and Storage in an OCI registry
> > - Bring-your-own PKI
> > 
> > Maintainer: Rafael Sadowski <[email protected]>
> > 
> > WWW: https://www.sigstore.dev/
> > 
> > 
> 
> Now with attachment, submitting new ports does involve this extra task ;)

Warning: cosign-3.1.2 conflicts with xmlrpc-epi-0.54.1p1 (net/xmlrpc-epi):/usr/local/bin/sample

Drop bin/sample if it's only intended to be a test file?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.