SigstoreBundle (container/bundle.rs on main) has from_keyless_signature, to_json and from_json — it can emit wsc's own signatures in bundle form, but there is no path from an existing cosign-produced bundle back into a KeylessSignature that the verifiers accept.
That makes wsc's verification usable only on artifacts wsc itself signed.
Why varve hits this
varve's release pipeline already produces cosign bundles today — SHA256SUMS.txt.cosign.bundle, keyless, GitHub OIDC, exactly the Sigstore shape wsc's verifiers understand. We wanted to verify those with wsc::airgapped rather than shelling out to cosign verify-blob.
We can't. The bundle has rekorBundle.{SignedEntryTimestamp, Payload} and a cert chain — all the inputs verify_signature needs — but nothing converts them into the struct it takes.
So the practical position is: an org already using cosign (which is most of them) cannot adopt wsc's offline verification without writing this adapter themselves, and each one will write it slightly differently against an internal struct shape.
Ask
A public constructor, roughly:
impl KeylessSignature {
/// Parse a cosign / Sigstore bundle (protobuf or the legacy JSON shape)
pub fn from_sigstore_bundle(json: &str) -> Result<Self, WSError>;
}
Two details worth deciding deliberately rather than discovering:
- Both bundle shapes exist in the wild. The legacy
rekorBundle JSON (what cosign v2.4.x writes, and what varve's release currently carries) and the newer protobuf bundle.sigstore.dev/v0.3 media type. Supporting only one will surprise someone.
- Round-trip fidelity.
from_sigstore_bundle → from_keyless_signature → to_json should be lossless, or the difference should be documented. A verifier that silently drops a field it did not model is how a check stops checking.
If it would help, varve's v0.28.0 bundle is a real, public, keyless-signed GitHub-OIDC artifact you can use as a fixture — and a negative control is easy to derive from it by flipping a byte of the digest.
Found while evaluating wsc for varve (DD-026). Related: sigil#256 (sign_digest), sigil#257 (0.11.0 unpublished), sigil#259 (stale embedded root).
SigstoreBundle(container/bundle.rsonmain) hasfrom_keyless_signature,to_jsonandfrom_json— it can emit wsc's own signatures in bundle form, but there is no path from an existing cosign-produced bundle back into aKeylessSignaturethat the verifiers accept.That makes wsc's verification usable only on artifacts wsc itself signed.
Why varve hits this
varve's release pipeline already produces cosign bundles today —
SHA256SUMS.txt.cosign.bundle, keyless, GitHub OIDC, exactly the Sigstore shape wsc's verifiers understand. We wanted to verify those withwsc::airgappedrather than shelling out tocosign verify-blob.We can't. The bundle has
rekorBundle.{SignedEntryTimestamp, Payload}and a cert chain — all the inputsverify_signatureneeds — but nothing converts them into the struct it takes.So the practical position is: an org already using cosign (which is most of them) cannot adopt wsc's offline verification without writing this adapter themselves, and each one will write it slightly differently against an internal struct shape.
Ask
A public constructor, roughly:
Two details worth deciding deliberately rather than discovering:
rekorBundleJSON (what cosign v2.4.x writes, and what varve's release currently carries) and the newer protobufbundle.sigstore.dev/v0.3media type. Supporting only one will surprise someone.from_sigstore_bundle→from_keyless_signature→to_jsonshould be lossless, or the difference should be documented. A verifier that silently drops a field it did not model is how a check stops checking.If it would help, varve's
v0.28.0bundle is a real, public, keyless-signed GitHub-OIDC artifact you can use as a fixture — and a negative control is easy to derive from it by flipping a byte of the digest.Found while evaluating wsc for varve (DD-026). Related: sigil#256 (
sign_digest), sigil#257 (0.11.0 unpublished), sigil#259 (stale embedded root).