Skip to content

installer: gate cosign-absent warning behind PEV_VERBOSE - #7

Open
samcofer wants to merge 1 commit into
mainfrom
pev-install-verbose-cosign-warning
Open

installer: gate cosign-absent warning behind PEV_VERBOSE#7
samcofer wants to merge 1 commit into
mainfrom
pev-install-verbose-cosign-warning

Conversation

@samcofer

Copy link
Copy Markdown
Collaborator

What

The installer prints a warning: cosign not on PATH; falling back to SHA-256 only line on every install where cosign isn't present. cosign is not a documented prerequisite for pev, so on the common path this reads like something went wrong when nothing did — it was the source of confusion reported in the field.

This routes that notice through a new vlog() helper that only prints when PEV_VERBOSE=1. The happy path stays quiet; operators auditing supply-chain verification can still surface the downgrade on demand.

Not changed

  • SHA-256 verification still always runs.
  • The hard-fail opt-in PEV_REQUIRE_COSIGN=1 is untouched — regulated installs that want a missing cosign to abort still get that.
  • When cosign is on PATH, signature verification is unchanged.

Safety note

vlog() ends in return 0 so the short-circuit [ ... ] && printf doesn't trip set -e when PEV_VERBOSE is unset. Verified with sh -n, shellcheck, and a set -eu behavior test in both quiet and verbose modes.

🤖 Generated with Claude Code

The SHA-256-only fallback warning printed on every install when cosign is
not on PATH. cosign is not a documented prerequisite, so for the common
case this is noise that reads like something went wrong.

Route the notice through a new vlog() helper that prints only when
PEV_VERBOSE=1, so operators auditing supply-chain verification can still
surface the downgrade while the happy path stays quiet. The hard-fail
opt-in (PEV_REQUIRE_COSIGN=1) is unchanged.

vlog() ends in `return 0` so the short-circuit `&&` test does not trip
`set -e` when PEV_VERBOSE is unset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant