Skip to content

feat: add sigstore cosign signing to release artifacts #3297

Description

@redhat-chai-bot

Summary

Release artifacts (tarballs, .deb/.rpm packages, checksums.txt) are currently published without sigstore signatures. Adding cosign signing would allow consumers to verify both integrity and authenticity of downloaded artifacts.

Today, checksums.txt provides integrity verification (detect corruption/tampering in transit), but there is no way to cryptographically verify that artifacts were produced by the tektoncd/cli release pipeline.

Current state

  • .goreleaser.yml has a checksum: section that generates checksums.txt (SHA256)
  • No signs: section exists in the goreleaser config
  • No .sig, .pem, .cert, or .bundle files are published with releases
  • No entries exist in the Rekor transparency log for any tektoncd/cli artifact
  • The tektoncd/actions/setup-tektoncd-cli action verifies checksums but cannot verify signatures since none exist

Proposed change

Add a signs: section to .goreleaser.yml to enable cosign keyless signing of the checksum file:

signs:
  - cmd: cosign
    artifacts: checksum
    args:
      - "sign-blob"
      - "--yes"
      - "--output-signature=${signature}"
      - "--output-certificate=${certificate}"
      - "${artifact}"

This would produce checksums.txt.sig and checksums.txt.pem alongside each release, allowing consumers to verify with:

cosign verify-blob \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp="https://github.com/tektoncd/cli" \
  --certificate-oidc-issuer="..." \
  checksums.txt

Infrastructure considerations

The goreleaser config change is straightforward, but the release pipeline runs goreleaser in a Tekton pod (goreleaser/goreleaser:v2.18.0 via PaC on pac.infra.tekton.dev), so there are infrastructure prerequisites:

  1. cosign in the goreleaser image — the stock goreleaser/goreleaser image does not include cosign. Options: use a custom image, add a cosign install step, or switch to an image that bundles both.
  2. OIDC identity for keyless signing — keyless cosign signing requires an OIDC token provider (e.g. Spire, Fulcio workload identity). Alternatively, a stored cosign key pair avoids the OIDC requirement.

Motivation

Downstream consumers install tkn in CI workflows and would like to verify release authenticity, not just integrity. Sigstore signing is a supply chain security best practice aligned with SLSA guidelines.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions