commitverification

package
v1.119.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DetectSignatureType added in v1.118.1

func DetectSignatureType(signature string) string

DetectSignatureType inspects the signature content to determine its type GitHub supports GPG, SSH, and S/MIME signatures Format references: - Git documentation: https://git-scm.com/docs/gitformat-signature - SSH format: https://blog.gitbutler.com/signing-commits-in-git-explained

Types

type CommitVerification

type CommitVerification struct {
	// Whether verification was attempted
	Attempted bool
	// Verification status
	Status VerificationStatus
	// Human-readable reason for the status
	Reason string
	// Platform that performed the verification (e.g., "github", "gitlab")
	Platform string
	// Optional: The signing key ID if verified
	KeyID string
	// Optional: The signature algorithm used
	SignatureAlgorithm string
}

CommitVerification represents the result of a commit signature verification

func VerifyGitHubCommit

func VerifyGitHubCommit(ctx context.Context, owner, repo, commitHash, token string, logger *zerolog.Logger) *CommitVerification

VerifyGitHubCommit verifies a commit signature using the GitHub API

func VerifyGitLabCommit

func VerifyGitLabCommit(ctx context.Context, baseURL, projectPath, commitHash string, credentials GitLabCredentials, logger *zerolog.Logger) *CommitVerification

VerifyGitLabCommit verifies a commit signature using the GitLab API

type GitLabCredentials added in v1.118.1

type GitLabCredentials struct {
	// APIToken is a personal, project or group access token with the read_api scope.
	// It is required to verify commits of private and internal projects.
	APIToken string
	// JobToken is the CI/CD job token. GitLab does not accept job tokens on the commit
	// signature endpoint and handles the request as anonymous, which only works for public projects.
	JobToken string
}

GitLabCredentials holds the tokens that can authenticate calls to the GitLab API

func GitLabCredentialsFromEnv added in v1.118.1

func GitLabCredentialsFromEnv() GitLabCredentials

GitLabCredentialsFromEnv reads the GitLab API credentials from GITLAB_TOKEN and CI_JOB_TOKEN

type VerificationStatus

type VerificationStatus int

VerificationStatus represents the status of a commit signature verification

const (
	// VerificationStatusUnspecified indicates an unspecified status
	VerificationStatusUnspecified VerificationStatus = iota
	// VerificationStatusVerified indicates the signature was successfully verified
	VerificationStatusVerified
	// VerificationStatusUnverified indicates the signature check failed or is invalid
	VerificationStatusUnverified
	// VerificationStatusUnavailable indicates verification could not be performed
	VerificationStatusUnavailable
	// VerificationStatusNotApplicable indicates no signature present or platform doesn't support it
	VerificationStatusNotApplicable
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL