Skip to content

Allow signers to specify allow list of oidc ids #1914

Allow signers to specify allow list of oidc ids

Allow signers to specify allow list of oidc ids #1914

Triggered via pull request October 18, 2023 18:21
Status Failure
Total duration 7m 23s
Artifacts

ci.yaml

on: pull_request
Matrix: build
Fit to window
Zoom out
Zoom in

Annotations

8 errors and 2 warnings
build (11): KeylessTest.java#L90
0.2sec dev.sigstore.KeylessTest > sign_failGithubOidcCheck() org.opentest4j.AssertionFailedError: expected: <Obtained Oidc Token OidcIdentity{identity=github machine, issuer=github.com} does not match any identities in allow list> but was: <Failed to obtain signing certificate> at app//org.junit.jupiter.api.AssertionFailureBuilder.build(AssertionFailureBuilder.java:151) at app//org.junit.jupiter.api.AssertionFailureBuilder.buildAndThrow(AssertionFailureBuilder.java:132) at app//org.junit.jupiter.api.AssertEquals.failNotEqual(AssertEquals.java:197) at app//org.junit.jupiter.api.AssertEquals.assertEquals(AssertEquals.java:182) at app//org.junit.jupiter.api.AssertEquals.assertEquals(AssertEquals.java:177) at app//org.junit.jupiter.api.Assertions.assertEquals(Assertions.java:1141) at app//dev.sigstore.KeylessTest.sign_failGithubOidcCheck(KeylessTest.java:90)
build (11): KeylessTest.java#L106
0.2sec dev.sigstore.KeylessTest > sign_passGithubOidcCheck() dev.sigstore.KeylessSignerException: Failed to obtain signing certificate at app//dev.sigstore.KeylessSigner.sign(KeylessSigner.java:276) at app//dev.sigstore.KeylessTest.sign_passGithubOidcCheck(KeylessTest.java:106) Caused by: dev.sigstore.KeylessSignerException: Obtained Oidc Token OidcIdentity{identity=repo:sigstore/sigstore-java:pull_request, issuer=https://token.actions.githubusercontent.com} does not match any identities in allow list at app//dev.sigstore.KeylessSigner.renewSigningCertificate(KeylessSigner.java:351) at app//dev.sigstore.KeylessSigner.sign(KeylessSigner.java:265) ... 1 more
build (11): task ':sigstore-java:test'#L1
Execution failed for task ':sigstore-java:test': org.gradle.api.internal.exceptions.MarkedVerificationException: There were failing tests. See the report at: file:///home/runner/work/sigstore-java/sigstore-java/sigstore-java/build/reports/tests/test/index.html
build (11)
Gradle build failed: see console output for details
build (17): KeylessTest.java#L90
0.5sec dev.sigstore.KeylessTest > sign_failGithubOidcCheck() org.opentest4j.AssertionFailedError: expected: <Obtained Oidc Token OidcIdentity{identity=github machine, issuer=github.com} does not match any identities in allow list> but was: <Failed to obtain signing certificate> at app//org.junit.jupiter.api.AssertionFailureBuilder.build(AssertionFailureBuilder.java:151) at app//org.junit.jupiter.api.AssertionFailureBuilder.buildAndThrow(AssertionFailureBuilder.java:132) at app//org.junit.jupiter.api.AssertEquals.failNotEqual(AssertEquals.java:197) at app//org.junit.jupiter.api.AssertEquals.assertEquals(AssertEquals.java:182) at app//org.junit.jupiter.api.AssertEquals.assertEquals(AssertEquals.java:177) at app//org.junit.jupiter.api.Assertions.assertEquals(Assertions.java:1141) at app//dev.sigstore.KeylessTest.sign_failGithubOidcCheck(KeylessTest.java:90)
build (17): KeylessTest.java#L106
0.4sec dev.sigstore.KeylessTest > sign_passGithubOidcCheck() dev.sigstore.KeylessSignerException: Failed to obtain signing certificate at app//dev.sigstore.KeylessSigner.sign(KeylessSigner.java:276) at app//dev.sigstore.KeylessTest.sign_passGithubOidcCheck(KeylessTest.java:106) Caused by: dev.sigstore.KeylessSignerException: Obtained Oidc Token OidcIdentity{identity=repo:sigstore/sigstore-java:pull_request, issuer=https://token.actions.githubusercontent.com} does not match any identities in allow list at app//dev.sigstore.KeylessSigner.renewSigningCertificate(KeylessSigner.java:351) at app//dev.sigstore.KeylessSigner.sign(KeylessSigner.java:265) ... 1 more
build (17): task ':sigstore-java:test'#L1
Execution failed for task ':sigstore-java:test': org.gradle.api.internal.exceptions.MarkedVerificationException: There were failing tests. See the report at: file:///home/runner/work/sigstore-java/sigstore-java/sigstore-java/build/reports/tests/test/index.html
build (17)
Gradle build failed: see console output for details
build (11)
Restore cache failed: Dependencies file is not found in /home/runner/work/sigstore-java/sigstore-java. Supported file pattern: go.sum
build (17)
Restore cache failed: Dependencies file is not found in /home/runner/work/sigstore-java/sigstore-java. Supported file pattern: go.sum