Summary
Release artifacts (tarballs, .deb/.rpm packages, checksums.txt) are currently published without sigstore signatures. Adding cosign signing would allow consumers to verify both integrity and authenticity of downloaded artifacts.
Today, checksums.txt provides integrity verification (detect corruption/tampering in transit), but there is no way to cryptographically verify that artifacts were produced by the tektoncd/cli release pipeline.
Current state
.goreleaser.yml has a checksum: section that generates checksums.txt (SHA256)
- No
signs: section exists in the goreleaser config
- No
.sig, .pem, .cert, or .bundle files are published with releases
- No entries exist in the Rekor transparency log for any tektoncd/cli artifact
- The
tektoncd/actions/setup-tektoncd-cli action verifies checksums but cannot verify signatures since none exist
Proposed change
Add a signs: section to .goreleaser.yml to enable cosign keyless signing of the checksum file:
signs:
- cmd: cosign
artifacts: checksum
args:
- "sign-blob"
- "--yes"
- "--output-signature=${signature}"
- "--output-certificate=${certificate}"
- "${artifact}"
This would produce checksums.txt.sig and checksums.txt.pem alongside each release, allowing consumers to verify with:
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp="https://github.com/tektoncd/cli" \
--certificate-oidc-issuer="..." \
checksums.txt
Infrastructure considerations
The goreleaser config change is straightforward, but the release pipeline runs goreleaser in a Tekton pod (goreleaser/goreleaser:v2.18.0 via PaC on pac.infra.tekton.dev), so there are infrastructure prerequisites:
- cosign in the goreleaser image — the stock
goreleaser/goreleaser image does not include cosign. Options: use a custom image, add a cosign install step, or switch to an image that bundles both.
- OIDC identity for keyless signing — keyless cosign signing requires an OIDC token provider (e.g. Spire, Fulcio workload identity). Alternatively, a stored cosign key pair avoids the OIDC requirement.
Motivation
Downstream consumers install tkn in CI workflows and would like to verify release authenticity, not just integrity. Sigstore signing is a supply chain security best practice aligned with SLSA guidelines.
Summary
Release artifacts (tarballs,
.deb/.rpmpackages,checksums.txt) are currently published without sigstore signatures. Adding cosign signing would allow consumers to verify both integrity and authenticity of downloaded artifacts.Today,
checksums.txtprovides integrity verification (detect corruption/tampering in transit), but there is no way to cryptographically verify that artifacts were produced by the tektoncd/cli release pipeline.Current state
.goreleaser.ymlhas achecksum:section that generateschecksums.txt(SHA256)signs:section exists in the goreleaser config.sig,.pem,.cert, or.bundlefiles are published with releasestektoncd/actions/setup-tektoncd-cliaction verifies checksums but cannot verify signatures since none existProposed change
Add a
signs:section to.goreleaser.ymlto enable cosign keyless signing of the checksum file:This would produce
checksums.txt.sigandchecksums.txt.pemalongside each release, allowing consumers to verify with:Infrastructure considerations
The goreleaser config change is straightforward, but the release pipeline runs goreleaser in a Tekton pod (
goreleaser/goreleaser:v2.18.0via PaC onpac.infra.tekton.dev), so there are infrastructure prerequisites:goreleaser/goreleaserimage does not include cosign. Options: use a custom image, add a cosign install step, or switch to an image that bundles both.Motivation
Downstream consumers install
tknin CI workflows and would like to verify release authenticity, not just integrity. Sigstore signing is a supply chain security best practice aligned with SLSA guidelines.