Skip to content

Installation script: Support checksum signature verification #1627

@hibare

Description

@hibare

What would you like to be added:

Grype simplifies the installation process through a convenient script. The current script includes a checksum validation step for the binary being installed. Since Grype utilizes cosign to sign the checksum file, it would be beneficial to enhance the installation script by incorporating checksum signature validation.

Why is this needed:

This enhancement ensures consumers can effortlessly verify the installation of binaries, eliminating the need for manual verification.

Additional context:

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions