Documentation
¶
Overview ¶
Package verify checks keyless Sigstore (cosign/Fulcio/Rekor) signatures on OCI images and on cosign bundle files, mirroring the sigstore-go verification examples.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Identity ¶
Identity constrains the signing certificate. At least one of SAN/SANRegexp must be set; OIDCIssuer/OIDCIssuerRegexp are optional but recommended.
type Option ¶
type Option func(*config)
Option configures Verify.
func WithCraneOptions ¶
WithCraneOptions targets a specific registry transport (e.g. tests).
func WithTrustedRootJSON ¶
WithTrustedRootJSON supplies a pinned trusted root (tests / air-gapped use). When absent, Verify fetches the public-good root over TUF.
type Result ¶
type Result struct {
Verified bool `json:"verified"`
Digest string `json:"digest,omitempty"`
Certificate struct {
Issuer string `json:"issuer"`
SAN string `json:"san"`
} `json:"certificate"`
}
Result reports the verification outcome.
func BundleFile ¶
BundleFile verifies a cosign/Sigstore bundle stored on disk against the supplied trusted root JSON and identity. It is the fully offline, deterministic entry point used in tests and for air-gapped verification of captured bundles.
func MessageSignatureBundleFile ¶
func MessageSignatureBundleFile(bundlePath string, trustedRootJSON []byte, id Identity) (*Result, error)
MessageSignatureBundleFile verifies an offline cosign MessageSignature bundle against the supplied trusted root and identity, using the bundle's own message digest as the artifact. It is the offline counterpart to Verify's OCI path.