Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do not fail verification if owners don't match #2550

Merged
merged 2 commits into from
Dec 7, 2018

Conversation

PatoBeltran
Copy link
Contributor

Bug

Fixes: NuGet/Home#7572

Fix

Details: When AllowListVerificationProvider matched a signing certificate with a trusted repository entry that has owners, it failed the whole allow list verification if those owners did not match any of the ones that signed the package. This becomes an issue if there's a trusted signer entry later in the list that does match this package (e.g. a trusted author for the author signature).

cc. @rido-min

@PatoBeltran PatoBeltran changed the base branch from release-4.9.2-rtm to release-4.9.3-rtm December 6, 2018 20:49
@PatoBeltran PatoBeltran merged commit 35b10dd into release-4.9.3-rtm Dec 7, 2018
@PatoBeltran PatoBeltran deleted the dev-pb-trustedSignersOrder branch December 7, 2018 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants