From 188fb38a175f0ae11671fcdea4a2a90b6457fc42 Mon Sep 17 00:00:00 2001 From: Tim Miller Date: Fri, 17 Jun 2022 11:16:51 -0400 Subject: [PATCH] Instead of continuing when Attestation data is not present, this should be failing with a clear error. Otherwise it will incorrectly return success --- cmd/cli/rekor/rekoruuid_validator.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/cmd/cli/rekor/rekoruuid_validator.go b/cmd/cli/rekor/rekoruuid_validator.go index bea88ab..567555c 100644 --- a/cmd/cli/rekor/rekoruuid_validator.go +++ b/cmd/cli/rekor/rekoruuid_validator.go @@ -38,7 +38,8 @@ func Validate(vendorFile config.VendorFile, downloadedFile string) (err error) { continue } if entry.Attestation == nil { - continue + color.Red(fmt.Sprintf("Cannot validate ` %s ` - Attestation data missing from Rekor", vendorFile.ReleaseFile)) + return &ImageValidationError{image: vendorFile.RekorUUID} } decoded, err := base64.StdEncoding.DecodeString(string(entry.Attestation.Data))