Skip to content

Fix OIDC Token fetch for tests - #102

Merged
ompushkara merged 1 commit into
mainfrom
check-oidc-fetch
Sep 10, 2026
Merged

ompushkara merged 1 commit into
mainfrom
check-oidc-fetch

Conversation

@ompushkara

Copy link
Copy Markdown

Summary

Checklist
  • All commits are signed-off, using DCO
  • All new code has docstrings and type annotations
  • All new code is covered by tests. Aim for at least 90% coverage. CI is configured to highlight lines not covered by tests.
  • Public facing changes are paired with documentation changes
  • Release note has been added to CHANGELOG.md if needed

@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Fetch OIDC test token directly from conformance storage

🐞 Bug fix 🧪 Tests 🕐 Less than 10 minutes

Grey Divider

AI Description

• Replace beacon repository cloning with direct OIDC token download.
• Pass the downloaded token directly to Sigstore signing compatibility tests.
Diagram

graph TD
  A(["Conformance Storage"]) -->|HTTPS token| B["curl fetch"] -->|id_token| C["Version Test"] -->|identity token| D["Sigstore Sign"]
Loading
High-Level Assessment

Directly downloading the published conformance token is the best fit for this test. It removes unnecessary repository cloning and temporary token-project setup while retaining fail-fast behavior; preserving the Git-based beacon checkout would add overhead and another failure point without improving coverage.

Files changed (1) +2 / -14

Bug fix (1) +2 / -14
test-sign-verify-allversions.shDownload the OIDC test token directly with curl +2/-14

Download the OIDC test token directly with curl

• Replaces the temporary beacon repository clone with a fail-fast curl request to Sigstore conformance storage. The downloaded token is retained in memory and passed directly to the Sigstore signing command.

scripts/tests/test-sign-verify-allversions.sh

@qodo-for-securesign

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can turn these tips off under Display preferences

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@codecov-commenter

codecov-commenter commented Sep 10, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.70%. Comparing base (718efec) to head (39996f3).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #102   +/-   ##
=======================================
  Coverage   79.70%   79.70%           
=======================================
  Files          21       21           
  Lines        1922     1922           
=======================================
  Hits         1532     1532           
  Misses        390      390           
Flag Coverage Δ
unit 79.70% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

…st failures

Signed-off-by: ompushkara <omotilal@redhat.com>
@sampras343

Copy link
Copy Markdown
Member

lgtm, you could also pull this instead sigstore#639

@ompushkara
ompushkara merged commit 8a1e52e into main Sep 10, 2026
55 checks passed
@ompushkara
ompushkara deleted the check-oidc-fetch branch September 10, 2026 11:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants