verify

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jun 24, 2026 License: Apache-2.0 Imports: 18 Imported by: 0

Documentation

Overview

Package verify checks keyless Sigstore (cosign/Fulcio/Rekor) signatures on OCI images and on cosign bundle files, mirroring the sigstore-go verification examples.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Identity

type Identity struct {
	OIDCIssuer       string
	OIDCIssuerRegexp string
	SAN              string
	SANRegexp        string
}

Identity constrains the signing certificate. At least one of SAN/SANRegexp must be set; OIDCIssuer/OIDCIssuerRegexp are optional but recommended.

type Option

type Option func(*config)

Option configures Verify.

func WithCraneOptions

func WithCraneOptions(opts ...crane.Option) Option

WithCraneOptions targets a specific registry transport (e.g. tests).

func WithTrustedRootJSON

func WithTrustedRootJSON(b []byte) Option

WithTrustedRootJSON supplies a pinned trusted root (tests / air-gapped use). When absent, Verify fetches the public-good root over TUF.

type Result

type Result struct {
	Verified    bool   `json:"verified"`
	Digest      string `json:"digest,omitempty"`
	Certificate struct {
		Issuer string `json:"issuer"`
		SAN    string `json:"san"`
	} `json:"certificate"`
}

Result reports the verification outcome.

func BundleFile

func BundleFile(bundlePath string, trustedRootJSON []byte, id Identity) (*Result, error)

BundleFile verifies a cosign/Sigstore bundle stored on disk against the supplied trusted root JSON and identity. It is the fully offline, deterministic entry point used in tests and for air-gapped verification of captured bundles.

func MessageSignatureBundleFile

func MessageSignatureBundleFile(bundlePath string, trustedRootJSON []byte, id Identity) (*Result, error)

MessageSignatureBundleFile verifies an offline cosign MessageSignature bundle against the supplied trusted root and identity, using the bundle's own message digest as the artifact. It is the offline counterpart to Verify's OCI path.

func Verify

func Verify(ctx context.Context, ref string, id Identity, opts ...Option) (*Result, error)

Verify checks the keyless cosign signature on the OCI image ref against the given identity, verifying the signature, transparency-log inclusion, and certificate.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL