attest

package
v0.7.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 30 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// ExpectedIssuer is the OIDC issuer found in the sigstore bundles
	ExpectedIssuer = "https://token.actions.githubusercontent.com"

	// ExpectedSanPrefix is the prefix of the identity of the reusable workflow
	// signing the provenance and VSAs. The full identity ends with the git
	// reference the workflow was pinned to, which varies across users and
	// releases.
	ExpectedSanPrefix = "https://github.com/slsa-framework/actions/.github/workflows/compute_slsa_source.yml@"

	// LegacySourceActionsSan is the identity of the workflow that signed
	// attestations while the actions lived in slsa-framework/source-actions.
	LegacySourceActionsSan = "https://github.com/slsa-framework/source-actions/.github/workflows/compute_slsa_source.yml@refs/heads/main"

	// LegacyPocSan is the identity of the workflow that signed attestations
	// before the actions were split out of the slsa-source-poc repository.
	//
	// See https://github.com/slsa-framework/source-tool/issues/255
	LegacyPocSan = "https://github.com/slsa-framework/slsa-source-poc/.github/workflows/compute_slsa_source.yml@refs/heads/main"
)
View Source
const (
	VsaPredicateType = "https://slsa.dev/verification_summary/v1"

	// VsaVerifierId identifies the verifier issuing the VSAs: the repository
	// hosting the workflow that runs sourcetool to verify the source.
	VsaVerifierId = "https://github.com/slsa-framework/actions"

	// LegacySourceActionsVsaVerifierId is the verifier ID of the VSAs issued
	// while the actions lived in slsa-framework/source-actions.
	LegacySourceActionsVsaVerifierId = "https://github.com/slsa-framework/source-actions"

	// LegacyPocVsaVerifierId is the verifier ID of the VSAs issued before the
	// actions were split out of the slsa-source-poc repository.
	LegacyPocVsaVerifierId = "https://github.com/slsa-framework/slsa-source-poc"
)

Variables

Predicate type sets used when fetching attestations for a revision.

AcceptedVsaVerifierIds lists the verifier IDs accepted when reading VSAs from a repository: the current one and the legacy IDs found in VSAs issued before the actions moved to their current repository.

DefaultVerifierOptions accept attestations signed by the current provenance workflow, whatever reference it is pinned to, and by the legacy workflows while repositories still carry attestations signed by them.

Functions

func CreateUnsignedSourceVsa

func CreateUnsignedSourceVsa(branch *models.Branch, commit *models.Commit, verifiedLevels slsa.SourceVerifiedLevels, policy string) (string, error)

func Debugf

func Debugf(format string, args ...any)

func GetSourceProvPred

func GetSourceProvPred(statement *intoto.Statement) (*provenance.SourceProvenancePred, error)

func GetSourceRefsForCommit

func GetSourceRefsForCommit(att attestation.Envelope, commit *models.Commit) ([]string, error)

GetSourceRefsForCommit returns the source branch annotations from the subject

func GetSubjectForCommit

func GetSubjectForCommit(att attestation.Envelope, commit *models.Commit) *intoto.ResourceDescriptor

Returns the _first_ subject that includes the commit. TODO: add support for multiple subjects...

func GetTagProvPred

func GetTagProvPred(statement *intoto.Statement) (*provenance.TagProvenancePred, error)

func IsAcceptedVsaVerifierId added in v0.7.1

func IsAcceptedVsaVerifierId(id string) bool

IsAcceptedVsaVerifierId returns true if the verifier ID is one of the IDs accepted when reading VSAs.

func Sign

func Sign(data string) (string, error)

func StatementToString

func StatementToString(stmt *intoto.Statement) string

Just make this easy for logging...

func WithAuthenticator added in v0.7.0

func WithAuthenticator(athn *auth.Authenticator) optFn

func WithBackend added in v0.7.0

func WithBackend(b models.VcsBackend) optFn

func WithGithubCollector added in v0.7.0

func WithGithubCollector(yesno bool) optFn

func WithNotesCollector added in v0.7.0

func WithNotesCollector(yesno bool) optFn

func WithRepository added in v0.7.0

func WithRepository(repos ...string) optFn

func WithRetries added in v0.7.0

func WithRetries(r uint8) optFn

func WithVerifier added in v0.7.0

func WithVerifier(vf Verifier) optFn

Types

type Attester added in v0.7.0

type Attester struct {
	Options AttesterOptions
	// contains filtered or unexported fields
}

func NewAttester added in v0.7.0

func NewAttester(fn ...optFn) (*Attester, error)

NewAttester creates a new attester

func (*Attester) CreateSourceProvenance added in v0.7.0

func (a *Attester) CreateSourceProvenance(ctx context.Context, branch *models.Branch, commit *models.Commit) (*intoto.Statement, error)

prevAttPath string

func (*Attester) CreateTagProvenance added in v0.7.0

func (a *Attester) CreateTagProvenance(ctx context.Context, branch *models.Branch, tag *models.Tag, actor string) (*intoto.Statement, error)

CreateTagProvenance creates a provenance statement for a tag.

func (*Attester) FetchRevisionAttestations added in v0.7.1

func (a *Attester) FetchRevisionAttestations(ctx context.Context, branch *models.Branch, commit *models.Commit, predicateTypes ...attestation.PredicateType) ([]FetchedEnvelope, error)

FetchRevisionAttestations returns the attestations stored for a commit that match any of the given predicate types. Unlike GetRevisionVSA and GetRevisionProvenance it does not discard envelopes that fail verification. Each returned entry carries the result of verifying it so callers can decide what to do with an attestation that fails.

func (*Attester) GetRevisionProvenance added in v0.7.0

func (a *Attester) GetRevisionProvenance(ctx context.Context, branch *models.Branch, commit *models.Commit) (*provenance.SourceProvenancePred, error)

GetRevisionProvenance returns the provenance attestation for a commit by querying the configured collectors.

func (*Attester) GetRevisionVSA added in v0.7.0

func (a *Attester) GetRevisionVSA(ctx context.Context, branch *models.Branch, revision models.Revision) (attestation.Envelope, *vsa.VerificationSummary, error)

GetRevisionVSA returns a revision's VSA attestation

func (*Attester) Validate added in v0.7.0

func (a *Attester) Validate() error

Validate checks that the attester configuration is complete

type AttesterOptions added in v0.7.0

type AttesterOptions struct {
	// Initialize dynamic notes fetcher and storer
	InitNotesCollector bool

	// Initialize attestations store collector and storer
	InitGHCollector bool

	// Additional read repositories
	Repos []string

	// Times to retry fetching attestations
	Retries uint8
}

type BndVerifier

type BndVerifier struct {
	Options VerificationOptions
}

func NewBndVerifier

func NewBndVerifier(opts VerificationOptions) *BndVerifier

func (*BndVerifier) Verify

func (bv *BndVerifier) Verify(data string) (*verify.VerificationResult, error)

Verify checks a signed bundle, ensuring the signer matches the expected identity. Note that this method does not accept the alternate identities, only the expected SAN (or prefix) is checked.

func (*BndVerifier) VerifyEnvelope added in v0.7.0

func (bv *BndVerifier) VerifyEnvelope(env attestation.Envelope) error

VerifyEnvelope verifies the signature of an attestation envelope fetched by the collector and checks that the signer matches one of the expected identities.

type FetchedEnvelope added in v0.7.1

type FetchedEnvelope struct {
	PredicateType string
	Data          []byte
	Raw           []byte
	VerifyErr     error
}

FetchedEnvelope carries an attestation fetched for a revision together with its predicate type, its serialized predicate data, the envelope as stored in the backing system, and the result of verifying its signature and signer identity.

type VerificationOptions

type VerificationOptions struct {
	// ExpectedIssuer is the OIDC issuer of the certificates signing the
	// attestations. It is required, no identity is accepted without it.
	ExpectedIssuer string

	// ExpectedSan pins the signer identity to an exact subject alternative
	// name. When set, ExpectedSanPrefix is ignored.
	ExpectedSan string

	// ExpectedSanPrefix accepts any signer identity starting with the
	// prefix. Users pin the provenance workflow to different tags and
	// digests, so the git reference ending its identity varies.
	ExpectedSanPrefix string

	// AlternateSans lists additional signer identities accepted (exactly)
	// when verifying attestations. It carries the identities of the
	// workflows that signed attestations before the actions moved to their
	// current repository.
	//
	// See https://github.com/slsa-framework/source-tool/issues/255
	AlternateSans []string
}

func (*VerificationOptions) String added in v0.7.1

func (vo *VerificationOptions) String() string

String describes the accepted identities for error messages

type Verifier

type Verifier interface {
	Verify(data string) (*verify.VerificationResult, error)

	// VerifyEnvelope checks the cryptographic signature of a parsed
	// attestation envelope and ensures the signer matches the expected
	// identity. Envelopes that carry no verifiable signature (eg bare
	// statements) must return an error.
	VerifyEnvelope(env attestation.Envelope) error
}

func GetDefaultVerifier

func GetDefaultVerifier() Verifier

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL