Directories
¶
| Path | Synopsis |
|---|---|
|
Package auth implements pvtr's OIDC device-grant login and credential storage for authenticated publishing to grc.store.
|
Package auth implements pvtr's OIDC device-grant login and credential storage for authenticated publishing to grc.store. |
|
Package install installs Privateer plugins — from grc.store (pulled and verified end-to-end) or from a local binary path.
|
Package install installs Privateer plugins — from grc.store (pulled and verified end-to-end) or from a local binary path. |
|
Package oci holds the grc.store OCI mechanics shared by `pvtr publish` (push a signed plugin index) and `pvtr install` (pull + verify one).
|
Package oci holds the grc.store OCI mechanics shared by `pvtr publish` (push a signed plugin index) and `pvtr install` (pull + verify one). |
|
Package publish is the grc.store producer path: assemble a multi-platform OCI plugin index from a GoReleaser dist directory, push it to the hub's registry, keyless-sign it, and /sync so the hub ingests and verifies it.
|
Package publish is the grc.store producer path: assemble a multi-platform OCI plugin index from a GoReleaser dist directory, push it to the hub's registry, keyless-sign it, and /sync so the hub ingests and verifies it. |
|
Package verify implements the §6 consumer verification contract for grc.store-sourced plugins: keyless signature verification over a pinned public-good Sigstore trusted root, an identity policy (camp (b) TOFU), and the full digest-chain walk index → child → config/layer → bytes.
|
Package verify implements the §6 consumer verification contract for grc.store-sourced plugins: keyless signature verification over a pinned public-good Sigstore trusted root, an identity policy (camp (b) TOFU), and the full digest-chain walk index → child → config/layer → bytes. |
Click to show internal directories.
Click to hide internal directories.