mirror of
https://github.com/freedomofpress/dangerzone.git
synced 2025-05-04 04:31:49 +02:00
fixup! Download and verify cosign signatures
This commit is contained in:
parent
22d235cabd
commit
5a4ddb17c9
1 changed files with 3 additions and 0 deletions
|
@ -255,6 +255,9 @@ def convert_oci_images_signatures(
|
|||
layers = signatures_manifest.get("layers", [])
|
||||
signatures = [_to_cosign_signature(layer) for layer in layers]
|
||||
|
||||
if not signatures:
|
||||
raise errors.SignatureExtractionError()
|
||||
|
||||
payload_location = _get_blob(tmpdir, layers[0]["digest"])
|
||||
with open(payload_location, "r") as f:
|
||||
payload = json.load(f)
|
||||
|
|
Loading…
Reference in a new issue