Skip to content

Verify Rekor-provided time with SET before use#307

Open
Hayden-IO wants to merge 1 commit into
mainfrom
bugfix
Open

Verify Rekor-provided time with SET before use#307
Hayden-IO wants to merge 1 commit into
mainfrom
bugfix

Conversation

@Hayden-IO

Copy link
Copy Markdown
Contributor

sigstore-ruby accepted a Sigstore bundle whose Rekor v1 transparency log entry contains an inclusion proof and checkpoint, but did not contain a Signed Entry Timestamp (SET). The verifier then used the associated integratedTime as signing-time evidence even though that timestamp was not signed by Rekor.

Signed-off-by: Andrew Pan <andrew.pan@trailofbits.com>
@Hayden-IO Hayden-IO requested review from segiddins and tnytown June 17, 2026 20:42
@Hayden-IO

Copy link
Copy Markdown
Contributor Author

I'll need some help with why the tests are failing, not sure if we just need to bump some Ruby deps?

@segiddins

Copy link
Copy Markdown
Member

I'm about to push up a pr that bumps the conformance suite and adds rekorv2 support

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants