Page link
https://kyverno.io/docs/policy-types/cluster-policy/verify-images/sigstore/#keyless-signing-and-verification
Description
The Keyless signing and verification section contains two examples.
The first one uses the ghcr.io/kyverno/test-verify-image:signed-keyless image and correctly references the subject as *@nirmata.com.
The second one uses the same image, but uses a subjectRegExp that has github.com instead of the *@nirmata.com email address. Also the issuerRegExp is using Github instead of accounts.google.com.
Expected behavior
The examples should be consistent, i.e. using the same image they should both use the same subject and issuer values.
Slack discussion
No response
Page link
https://kyverno.io/docs/policy-types/cluster-policy/verify-images/sigstore/#keyless-signing-and-verification
Description
The
Keyless signing and verificationsection contains two examples.The first one uses the
ghcr.io/kyverno/test-verify-image:signed-keylessimage and correctly references thesubjectas*@nirmata.com.The second one uses the same image, but uses a
subjectRegExpthat hasgithub.cominstead of the*@nirmata.comemail address. Also theissuerRegExpis using Github instead of accounts.google.com.Expected behavior
The examples should be consistent, i.e. using the same image they should both use the same
subjectandissuervalues.Slack discussion
No response