diff --git a/pkg/attest/sign_test.go b/pkg/attest/sign_test.go index 047792a..bc7e112 100644 --- a/pkg/attest/sign_test.go +++ b/pkg/attest/sign_test.go @@ -223,7 +223,7 @@ func TestSimpleStatementSigning(t *testing.T) { assert.Equal(t, subject.MediaType, mf.MediaType) assert.Equal(t, empty, mf.Config.MediaType) assert.Equal(t, int64(2), mf.Config.Size) - assert.Equal(t, "e30=", string(mf.Config.Data)) + assert.Equal(t, "{}", string(mf.Config.Data)) layers, err := img.Layers() require.NoError(t, err) assert.Len(t, layers, 1) diff --git a/pkg/attest/verify.go b/pkg/attest/verify.go index e0b8dc5..db33043 100644 --- a/pkg/attest/verify.go +++ b/pkg/attest/verify.go @@ -166,11 +166,6 @@ func VerifyAttestations(ctx context.Context, resolver oci.AttestationResolver, p } func NewAttestationManifest(subject *v1.Descriptor) (*attestation.AttestationManifest, error) { - subjectDigest := subject.Digest.String() - subject.Annotations = map[string]string{ - "vnd.docker.reference.digest": subjectDigest, - "vnd.docker.reference.type": "attestation-manifest"} - return &attestation.AttestationManifest{ OriginalDescriptor: &v1.Descriptor{ MediaType: "application/vnd.oci.image.manifest.v1+json", diff --git a/pkg/attestation/attestation.go b/pkg/attestation/attestation.go index 425ac85..aa3d9a2 100644 --- a/pkg/attestation/attestation.go +++ b/pkg/attestation/attestation.go @@ -303,7 +303,7 @@ func (i *EmptyConfigImage) Manifest() (*v1.Manifest, error) { MediaType: "application/vnd.oci.empty.v1+json", Size: 2, Digest: v1.Hash{Algorithm: "sha256", Hex: "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a"}, - Data: []byte("e30="), + Data: []byte("{}"), } return mf, nil }