Self-hosting and infrastructure enthusiast. Background in statistical physics and high performance computing
- Seattle
- https://www.nfsmith.ca
- @nfsmithca
Block or Report
Block or report nsmith5
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
-
-
road-to-secure-kubernetes Public
Hardening a sketchy containerized application one step at a time
-
1,055 contributions in the last year
Activity overview
Contributed to
sigstore/fulcio,
nsmith5/rekor-sidekick,
circleci/circleci-docs
and 41 other
repositories
Contribution activity
May 2022
Created 18 commits in 3 repositories
Created 3 repositories
Created a pull request in sigstore/fulcio that received 18 comments
Adds new Github actions identity issuer
Summary Implements the new issuer abstraction for github actions OIDC issuer. Thoughts / questions for reviewers: I tried to centralize the pkix e…
+705
−0
•
18
comments
Opened 20 other pull requests in 3 repositories
sigstore/fulcio
1
open
1
closed
14
merged
- Move github principal to its own package
- [WIP] Move config and challenge result to legacy issuer package
- Correct SPIFFE trust domain checking
- Add some tests for challenges
- Refactor challenge verification
- identity: improve the documentation for Principal.Name()
- challenges: remove ParseCSR
- googleca: Don't log all identities
- Use GenerateSerialNumber from cryptoutils
-
Consume
identity.Principalin CA abstraction -
Small
carefactor -
Remove unused
Subjectfield fromCodeSigningCertificate - Add client options testing
- Refactor x509 extension embedding logic
- Add timeout to OIDC discovery
-
Add new
IssuerandPrincipalabstractions
sigstore/gitsign
3
merged
sigstore/sget
1
open
Reviewed 17 pull requests in 2 repositories
sigstore/fulcio
12 pull requests
- [WIP] Move config and challenge result to legacy issuer package
- cmd/app: remove dependency on deprecated github.com/pkg/errors
- Move domain validation checks for URI/Username to service startup
- Validate SPIFFE IDs and trust domains via library
- Correct SPIFFE trust domain checking
- Skip tests that require network access with HERMETIC=true
- Refactor challenge verification
-
Consume
identity.Principalin CA abstraction - Add client options testing
- Refactor x509 extension embedding logic
- Adds new Github actions identity issuer
-
Add new
IssuerandPrincipalabstractions
Opened 2 issues in 1 repository
sigstore/gitsign
2
closed
16
contributions
in private repositories
May 2 – May 19