Skip to content

Add ability to verify signatures performed with Cosign v3 in our policies #1237

@viccuad

Description

@viccuad

As explained in https://www.kubewarden.io/blog/2025/10/kubewarden-1.30-release,
due to the migration of Cosign from v2 to v3, the verify-image-signatures-policy and the cel-policy sigstore verification host calls are not able to verify signatures performed with Cosign v3.

Acceptance criteria

  • Ensure sigstore-rs supports the new bundle format of Cosign v3. There are already some PRs related to this work, see here
  • Consume sigstore-rs on policy-fetcher/policy-sdk-rust
  • Consume policy-sdk-rust if needed on policies and tag new releases. Remove README.md notes stating that they only validate cosign v2 signatures.

Metadata

Metadata

Assignees

Type

No type

Projects

Status

In Progress

Relationships

None yet

Development

No branches or pull requests

Issue actions