Hey folks, we (Kubernetes) use the rekor client directly from go in kubernetes-sigs/release-sdk: https://github.com/kubernetes-sigs/release-sdk/blob/83243fb51416adb402fbbb1e611e2861e8e8d008/sign/sign.go#L726
The issue is that GetRekorClient imports go-retryablehttp, which is MPL licensed and therefore not allowed in the CNCF.
Would it be generally possible to switch to an alternative?
Refers to kubernetes-sigs/release-sdk#197