mirror of
https://github.com/containers/podman.git
synced 2025-12-12 01:38:04 +08:00
Bumps [github.com/containers/image/v5](https://github.com/containers/image) from 5.13.2 to 5.14.0. - [Release notes](https://github.com/containers/image/releases) - [Commits](https://github.com/containers/image/compare/v5.13.2...v5.14.0) --- updated-dependencies: - dependency-name: github.com/containers/image/v5 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
32 lines
1003 B
Go
32 lines
1003 B
Go
package copy
|
|
|
|
import (
|
|
"github.com/containers/image/v5/signature"
|
|
"github.com/containers/image/v5/transports"
|
|
"github.com/pkg/errors"
|
|
)
|
|
|
|
// createSignature creates a new signature of manifest using keyIdentity.
|
|
func (c *copier) createSignature(manifest []byte, keyIdentity string) ([]byte, error) {
|
|
mech, err := signature.NewGPGSigningMechanism()
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "initializing GPG")
|
|
}
|
|
defer mech.Close()
|
|
if err := mech.SupportsSigning(); err != nil {
|
|
return nil, errors.Wrap(err, "Signing not supported")
|
|
}
|
|
|
|
dockerReference := c.dest.Reference().DockerReference()
|
|
if dockerReference == nil {
|
|
return nil, errors.Errorf("Cannot determine canonical Docker reference for destination %s", transports.ImageName(c.dest.Reference()))
|
|
}
|
|
|
|
c.Printf("Signing manifest\n")
|
|
newSig, err := signature.SignDockerManifest(manifest, dockerReference.String(), mech, keyIdentity)
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "creating signature")
|
|
}
|
|
return newSig, nil
|
|
}
|