github

package
v0.7.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 21 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// ActionsOrg and ActionsRepo point to the repository hosting the reusable
	// provenance workflow the generated workflow calls.
	ActionsOrg  = "slsa-framework"
	ActionsRepo = "actions"
)

Variables

InherentControls are the controls that are always true because we are in git and/org GitHub.

Functions

This section is empty.

Types

type Backend

type Backend struct {
	Options *models.BackendOptions
	// contains filtered or unexported fields
}

Backend implemets the GitHub sourcetool backend

func New

func New(options *models.BackendOptions, opts ...Option) *Backend

func (*Backend) CheckWorkflowFork

func (b *Backend) CheckWorkflowFork(r *models.Repository) error

CheckWorkflowFork verifies that the user has a fork of the repository we are configuring.

func (*Backend) ConfigureControls

func (b *Backend) ConfigureControls(r *models.Repository, branches []*models.Branch, configs []models.ControlConfiguration) error

ConfigureControls configure the SLSA controls in the repository

func (*Backend) ControlConfigurationDescr

func (b *Backend) ControlConfigurationDescr(branch *models.Branch, config models.ControlConfiguration) string

func (*Backend) ControlPrecheck

func (b *Backend) ControlPrecheck(
	r *models.Repository, branches []*models.Branch, config models.ControlConfiguration,
) (ok bool, remediationMessage string, remediateFn models.ControlPreRemediationFn, err error)

ControlPrecheck checks if the prerequisites to enable the controls are OK

func (*Backend) CreateRepoRuleset

func (b *Backend) CreateRepoRuleset(r *models.Repository, branches []*models.Branch) error

func (*Backend) CreateTagRuleset

func (b *Backend) CreateTagRuleset(r *models.Repository) error

func (*Backend) CreateWorkflowPR

func (b *Backend) CreateWorkflowPR(ctx context.Context, r *models.Repository, branches []*models.Branch) (*models.PullRequest, error)

CreateWorkflowPR creates the pull request to add the provenance workflow to the specified repository.

func (*Backend) FindProvenanceWorkflows added in v0.7.1

func (b *Backend) FindProvenanceWorkflows(ctx context.Context, branch *models.Branch) ([]*models.ProvenanceWorkflow, error)

FindProvenanceWorkflows returns the workflows in the branch that call the SLSA source actions, flagging those still calling them from a legacy repository.

func (*Backend) FindWorkflowPR

func (b *Backend) FindWorkflowPR(ctx context.Context, r *models.Repository) (*models.PullRequest, error)

FindWorkflowPR looks for an open pull request adding or updating the provenance workflow in the repository. Returns nil if none is found.

func (*Backend) GetBranchControls

func (b *Backend) GetBranchControls(ctx context.Context, branch *models.Branch) (*slsa.ControlSet, error)

func (*Backend) GetBranchControlsAtCommit

func (b *Backend) GetBranchControlsAtCommit(ctx context.Context, branch *models.Branch, commit *models.Commit) (*slsa.ControlSet, error)

GetBranchControlsAtCommit

func (*Backend) GetDefaultBranch added in v0.7.0

func (b *Backend) GetDefaultBranch(ctx context.Context, repo *models.Repository) (*models.Branch, error)

GetDefaultBranch returns the default branch

func (*Backend) GetLatestActionsTag added in v0.7.0

func (b *Backend) GetLatestActionsTag(ctx context.Context) (tag, digest string, err error)

GetLatestActionsTag queries GitHub and returns the name and commit digest of the latest release tag of the actions repository (ActionsOrg/ActionsRepo).

func (*Backend) GetLatestCommit

func (b *Backend) GetLatestCommit(ctx context.Context, r *models.Repository, branch *models.Branch) (*models.Commit, error)

GetLatestCommit returns the latest commit from a branch

func (*Backend) GetPreviousCommit added in v0.7.0

func (b *Backend) GetPreviousCommit(ctx context.Context, branch *models.Branch, commit *models.Commit) (*models.Commit, error)

GetPreviousCommit takes a commit in

func (*Backend) GetRevisionCommit added in v0.7.0

func (b *Backend) GetRevisionCommit(ctx context.Context, repo *models.Repository, rev models.Revision) (*models.Commit, error)

GetRevisionCommit returns the commit of a revision (or error)

func (*Backend) GetTagControls

func (b *Backend) GetTagControls(ctx context.Context, branch *models.Branch, tag *models.Tag) (*slsa.ControlSet, error)

type Option added in v0.7.1

type Option func(*Backend)

Option configures a GitHub backend.

func WithVerifier added in v0.7.1

func WithVerifier(verifier attest.Verifier) Option

WithVerifier configures the verifier used when reading prior attestations.

type Options

type Options struct {
	UseFork bool
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL