Recommended update for rekor
| Announcement ID: | SUSE-RU-2022:4502-1 |
|---|---|
| Rating: | moderate |
| References: | |
| Affected Products: |
|
An update that contains one feature can now be installed.
Description:
This update for rekor fixes the following issues:
Rekor was updated to 1.0.1 (jsc#SLE-23476):
-
stop inserting envelope hash for intoto:0.0.2 types into index
-
build with FIPSified go1.18.
updated to rekor 1.0.0 (jsc#SLE-23476):
- add description on /api/v1/index/retrieve endpoint
- Adding e2e test coverage
- export rekor build/version information
- Use POST instead of GET for /api/log/entries/retrieve metrics.
- Search through all shards when searching
- verify: verify checkpoint's STH against the inclusion proof root hash
- add ability to enable/disable specific rekor API endpoints
- enable configurable client retries with backoff in RekorClient
- remove dead code around api-key and timestamp references
- update swagger API version to 1.0.0
- remove unused RekorVersion API definition
- install gocovmerge in hack/tools
- add retry command line flag on rekor-cli
- Add some info and debug logging to commonly used funcs
updated to rekor 0.12.2 (jsc#SLE-23476):
- add description on /api/v1/index/retrieve endpoint
- Adding e2e test coverage
- export rekor build/version information
- Use POST instead of GET for /api/log/entries/retrieve metrics.
- Search through all shards when searching by hash
updated to rekor 0.12.1 (jsc#SLE-23476):
-
Rekor v0.12.1 comes with a breaking change to rekor-cli v0.12.1. Users of rekor-cli MUST upgrade to the latest version The addition of the intotov2 created a breaking change for the rekor-cli
-
What's Changed
-
fix: fix harness tests with intoto v0.0.2
- feat: add file based signer and password
- Adds new rekor metrics for latency and QPS.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2022-4502=1 -
Basesystem Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-4502=1
Package List:
-
openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)
- rekor-1.0.1-150400.4.6.1
-
Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64)
- rekor-1.0.1-150400.4.6.1