Documentation
¶
Index ¶
- Constants
- Variables
- func CreateUnsignedSourceVsa(branch *models.Branch, commit *models.Commit, ...) (string, error)
- func Debugf(format string, args ...any)
- func GetSourceProvPred(statement *intoto.Statement) (*provenance.SourceProvenancePred, error)
- func GetSourceRefsForCommit(att attestation.Envelope, commit *models.Commit) ([]string, error)
- func GetSubjectForCommit(att attestation.Envelope, commit *models.Commit) *intoto.ResourceDescriptor
- func GetTagProvPred(statement *intoto.Statement) (*provenance.TagProvenancePred, error)
- func IsAcceptedVsaVerifierId(id string) bool
- func Sign(data string) (string, error)
- func StatementToString(stmt *intoto.Statement) string
- func WithAuthenticator(athn *auth.Authenticator) optFn
- func WithBackend(b models.VcsBackend) optFn
- func WithGithubCollector(yesno bool) optFn
- func WithNotesCollector(yesno bool) optFn
- func WithRepository(repos ...string) optFn
- func WithRetries(r uint8) optFn
- func WithVerifier(vf Verifier) optFn
- type Attester
- func (a *Attester) CreateSourceProvenance(ctx context.Context, branch *models.Branch, commit *models.Commit) (*intoto.Statement, error)
- func (a *Attester) CreateTagProvenance(ctx context.Context, branch *models.Branch, tag *models.Tag, actor string) (*intoto.Statement, error)
- func (a *Attester) FetchRevisionAttestations(ctx context.Context, branch *models.Branch, commit *models.Commit, ...) ([]FetchedEnvelope, error)
- func (a *Attester) GetRevisionProvenance(ctx context.Context, branch *models.Branch, commit *models.Commit) (*provenance.SourceProvenancePred, error)
- func (a *Attester) GetRevisionVSA(ctx context.Context, branch *models.Branch, revision models.Revision) (attestation.Envelope, *vsa.VerificationSummary, error)
- func (a *Attester) Validate() error
- type AttesterOptions
- type BndVerifier
- type FetchedEnvelope
- type VerificationOptions
- type Verifier
Constants ¶
const ( // ExpectedIssuer is the OIDC issuer found in the sigstore bundles ExpectedIssuer = "https://token.actions.githubusercontent.com" // ExpectedSanPrefix is the prefix of the identity of the reusable workflow // signing the provenance and VSAs. The full identity ends with the git // reference the workflow was pinned to, which varies across users and // releases. ExpectedSanPrefix = "https://github.com/slsa-framework/actions/.github/workflows/compute_slsa_source.yml@" // LegacySourceActionsSan is the identity of the workflow that signed // attestations while the actions lived in slsa-framework/source-actions. LegacySourceActionsSan = "https://github.com/slsa-framework/source-actions/.github/workflows/compute_slsa_source.yml@refs/heads/main" // LegacyPocSan is the identity of the workflow that signed attestations // before the actions were split out of the slsa-source-poc repository. // // See https://github.com/slsa-framework/source-tool/issues/255 LegacyPocSan = "https://github.com/slsa-framework/slsa-source-poc/.github/workflows/compute_slsa_source.yml@refs/heads/main" )
const ( VsaPredicateType = "https://slsa.dev/verification_summary/v1" // VsaVerifierId identifies the verifier issuing the VSAs: the repository // hosting the workflow that runs sourcetool to verify the source. VsaVerifierId = "https://github.com/slsa-framework/actions" // LegacySourceActionsVsaVerifierId is the verifier ID of the VSAs issued // while the actions lived in slsa-framework/source-actions. LegacySourceActionsVsaVerifierId = "https://github.com/slsa-framework/source-actions" // LegacyPocVsaVerifierId is the verifier ID of the VSAs issued before the // actions were split out of the slsa-source-poc repository. LegacyPocVsaVerifierId = "https://github.com/slsa-framework/slsa-source-poc" )
Variables ¶
var ( ProvenancePredicateTypes = []attestation.PredicateType{ attestation.PredicateType(provenance.SourceProvPredicateType), attestation.PredicateType(provenance.TagProvPredicateType), attestation.PredicateType(provenance.SourceProvPredicateTypeDraft), attestation.PredicateType(provenance.TagProvPredicateTypeDraft), } VSAPredicateTypes = []attestation.PredicateType{ attestation.PredicateType(VsaPredicateType), } )
Predicate type sets used when fetching attestations for a revision.
var AcceptedVsaVerifierIds = []string{ VsaVerifierId, LegacySourceActionsVsaVerifierId, LegacyPocVsaVerifierId, }
AcceptedVsaVerifierIds lists the verifier IDs accepted when reading VSAs from a repository: the current one and the legacy IDs found in VSAs issued before the actions moved to their current repository.
var DefaultVerifierOptions = VerificationOptions{ ExpectedIssuer: ExpectedIssuer, ExpectedSanPrefix: ExpectedSanPrefix, AlternateSans: []string{LegacySourceActionsSan, LegacyPocSan}, }
DefaultVerifierOptions accept attestations signed by the current provenance workflow, whatever reference it is pinned to, and by the legacy workflows while repositories still carry attestations signed by them.
Functions ¶
func CreateUnsignedSourceVsa ¶
func GetSourceProvPred ¶
func GetSourceProvPred(statement *intoto.Statement) (*provenance.SourceProvenancePred, error)
func GetSourceRefsForCommit ¶
GetSourceRefsForCommit returns the source branch annotations from the subject
func GetSubjectForCommit ¶
func GetSubjectForCommit(att attestation.Envelope, commit *models.Commit) *intoto.ResourceDescriptor
Returns the _first_ subject that includes the commit. TODO: add support for multiple subjects...
func GetTagProvPred ¶
func GetTagProvPred(statement *intoto.Statement) (*provenance.TagProvenancePred, error)
func IsAcceptedVsaVerifierId ¶ added in v0.7.1
IsAcceptedVsaVerifierId returns true if the verifier ID is one of the IDs accepted when reading VSAs.
func StatementToString ¶
Just make this easy for logging...
func WithAuthenticator ¶ added in v0.7.0
func WithAuthenticator(athn *auth.Authenticator) optFn
func WithBackend ¶ added in v0.7.0
func WithBackend(b models.VcsBackend) optFn
func WithGithubCollector ¶ added in v0.7.0
func WithGithubCollector(yesno bool) optFn
func WithNotesCollector ¶ added in v0.7.0
func WithNotesCollector(yesno bool) optFn
func WithRepository ¶ added in v0.7.0
func WithRepository(repos ...string) optFn
func WithRetries ¶ added in v0.7.0
func WithRetries(r uint8) optFn
func WithVerifier ¶ added in v0.7.0
func WithVerifier(vf Verifier) optFn
Types ¶
type Attester ¶ added in v0.7.0
type Attester struct {
Options AttesterOptions
// contains filtered or unexported fields
}
func NewAttester ¶ added in v0.7.0
NewAttester creates a new attester
func (*Attester) CreateSourceProvenance ¶ added in v0.7.0
func (a *Attester) CreateSourceProvenance(ctx context.Context, branch *models.Branch, commit *models.Commit) (*intoto.Statement, error)
prevAttPath string
func (*Attester) CreateTagProvenance ¶ added in v0.7.0
func (a *Attester) CreateTagProvenance(ctx context.Context, branch *models.Branch, tag *models.Tag, actor string) (*intoto.Statement, error)
CreateTagProvenance creates a provenance statement for a tag.
func (*Attester) FetchRevisionAttestations ¶ added in v0.7.1
func (a *Attester) FetchRevisionAttestations(ctx context.Context, branch *models.Branch, commit *models.Commit, predicateTypes ...attestation.PredicateType) ([]FetchedEnvelope, error)
FetchRevisionAttestations returns the attestations stored for a commit that match any of the given predicate types. Unlike GetRevisionVSA and GetRevisionProvenance it does not discard envelopes that fail verification. Each returned entry carries the result of verifying it so callers can decide what to do with an attestation that fails.
func (*Attester) GetRevisionProvenance ¶ added in v0.7.0
func (a *Attester) GetRevisionProvenance(ctx context.Context, branch *models.Branch, commit *models.Commit) (*provenance.SourceProvenancePred, error)
GetRevisionProvenance returns the provenance attestation for a commit by querying the configured collectors.
func (*Attester) GetRevisionVSA ¶ added in v0.7.0
func (a *Attester) GetRevisionVSA(ctx context.Context, branch *models.Branch, revision models.Revision) (attestation.Envelope, *vsa.VerificationSummary, error)
GetRevisionVSA returns a revision's VSA attestation
type AttesterOptions ¶ added in v0.7.0
type BndVerifier ¶
type BndVerifier struct {
Options VerificationOptions
}
func NewBndVerifier ¶
func NewBndVerifier(opts VerificationOptions) *BndVerifier
func (*BndVerifier) Verify ¶
func (bv *BndVerifier) Verify(data string) (*verify.VerificationResult, error)
Verify checks a signed bundle, ensuring the signer matches the expected identity. Note that this method does not accept the alternate identities, only the expected SAN (or prefix) is checked.
func (*BndVerifier) VerifyEnvelope ¶ added in v0.7.0
func (bv *BndVerifier) VerifyEnvelope(env attestation.Envelope) error
VerifyEnvelope verifies the signature of an attestation envelope fetched by the collector and checks that the signer matches one of the expected identities.
type FetchedEnvelope ¶ added in v0.7.1
FetchedEnvelope carries an attestation fetched for a revision together with its predicate type, its serialized predicate data, the envelope as stored in the backing system, and the result of verifying its signature and signer identity.
type VerificationOptions ¶
type VerificationOptions struct {
// ExpectedIssuer is the OIDC issuer of the certificates signing the
// attestations. It is required, no identity is accepted without it.
ExpectedIssuer string
// ExpectedSan pins the signer identity to an exact subject alternative
// name. When set, ExpectedSanPrefix is ignored.
ExpectedSan string
// ExpectedSanPrefix accepts any signer identity starting with the
// prefix. Users pin the provenance workflow to different tags and
// digests, so the git reference ending its identity varies.
ExpectedSanPrefix string
// AlternateSans lists additional signer identities accepted (exactly)
// when verifying attestations. It carries the identities of the
// workflows that signed attestations before the actions moved to their
// current repository.
//
// See https://github.com/slsa-framework/source-tool/issues/255
AlternateSans []string
}
func (*VerificationOptions) String ¶ added in v0.7.1
func (vo *VerificationOptions) String() string
String describes the accepted identities for error messages
type Verifier ¶
type Verifier interface {
Verify(data string) (*verify.VerificationResult, error)
// VerifyEnvelope checks the cryptographic signature of a parsed
// attestation envelope and ensures the signer matches the expected
// identity. Envelopes that carry no verifiable signature (eg bare
// statements) must return an error.
VerifyEnvelope(env attestation.Envelope) error
}
func GetDefaultVerifier ¶
func GetDefaultVerifier() Verifier