add v0.3 bundle support to DSSEBundleBuilder #1102
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Builds on #1093, updates the
@sigstore/sign
package to expose the option to generate v0.3-style Sigstore bundles. In order to ensure backward compatibility, the new flag is optional and defaults to generating v0.2 bundles.Other than the new media type, the defining characteristic of v0.3 bundles is the use of the single
certificate
field in theverificationMaterial
message -- this is why the newly-introduced flag is calledsingleCertificate
.Setting this new flag to
false
or leaving itundefined
will cause v0.2 bundles to be generated.