From 6391fc8e6c088522867b5c058056bd7cbc933730 Mon Sep 17 00:00:00 2001 From: Ronen Slavin Date: Mon, 31 Aug 2026 15:11:37 +0300 Subject: [PATCH] feat(attest): add source-path and skip-source-tree-check inputs Passes --source-path and --skip-source-tree-check through to cimon attest generate-and-sign, for pipelines where the source checkout lives outside the runner workspace and automatic discovery cannot reach it. Both inputs require a cimon binary that supports source resolution (v1.0.24 or later); leaving them unset keeps the previous behavior with any binary. Co-Authored-By: Claude Fable 5 --- attest/README.md | 2 ++ attest/action.yml | 13 +++++++++++++ attest/dist/index.js | 8 ++++++++ attest/index.js | 8 ++++++++ 4 files changed, 31 insertions(+) diff --git a/attest/README.md b/attest/README.md index 09de488..b4e8bed 100644 --- a/attest/README.md +++ b/attest/README.md @@ -60,6 +60,8 @@ See the inputs section below for the full list. | Name | Description | Default | |---|---|---| | `subjects` | Whitespace-separated list of artifact paths or base64 subjects | — | +| `source-path` | Path to the source checkout recorded in the attestation. Unset means automatic discovery (subject paths, run-id directory, workspace). Requires cimon v1.0.24 or later | — | +| `skip-source-tree-check` | Skip verifying the source tree matches the recorded commit | `false` | | `sign-key` | Path to a private ECDSA/RSA/ED25519 PEM key | — | | `keyless` | Use keyless (Sigstore) signing | `false` | | `tlog-upload` | Upload signature to Rekor transparency log | `true` | diff --git a/attest/action.yml b/attest/action.yml index 71feb65..098c4e6 100644 --- a/attest/action.yml +++ b/attest/action.yml @@ -22,6 +22,19 @@ inputs: description: A white space seperated list of paths, or base64-encoded subjects. Each path can be file, directory or image reference required: false default: '' + source-path: + description: | + Path to the source checkout recorded in the attestation's + resolvedDependencies. When unset, cimon discovers the source + automatically: from the subject paths, a directory named after the + CI run id, or the workspace. Set this when the source is checked + out to a location discovery cannot reach. + required: false + default: '' + skip-source-tree-check: + description: Skip verifying that the source working tree matches the recorded commit (faster on very large trees) + required: false + default: 'false' image-ref: description: (deprecated) The container reference to generate provenance for. Either subjects or imageRef are required required: false diff --git a/attest/dist/index.js b/attest/dist/index.js index d9106b7..261c50d 100644 --- a/attest/dist/index.js +++ b/attest/dist/index.js @@ -127702,6 +127702,10 @@ function getActionConfig() { ), provenanceOutput: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getInput('provenance-output'), signedProvenanceOutput: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getInput('signed-provenance-output'), + sourcePath: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getInput('source-path'), + skipSourceTreeCheck: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getBooleanInput( + 'skip-source-tree-check' + ), }, report: { reportJobSummary: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getBooleanInput('report-job-summary'), @@ -127789,6 +127793,10 @@ async function run(config) { if (config.attest.signedProvenanceOutput !== '') args.push('--output-signed-prov', config.attest.signedProvenanceOutput); if (config.attest.signKey !== '') args.push('--key', config.attest.signKey); + if (config.attest.sourcePath !== '') + args.push('--source-path', config.attest.sourcePath); + if (config.attest.skipSourceTreeCheck) + args.push('--skip-source-tree-check'); if (config.cimon.clientId !== '') args.push('--client-id', config.cimon.clientId); if (config.cimon.secret !== '') args.push('--secret', config.cimon.secret); diff --git a/attest/index.js b/attest/index.js index 7d3f7fc..3935ace 100644 --- a/attest/index.js +++ b/attest/index.js @@ -142,6 +142,10 @@ function getActionConfig() { ), provenanceOutput: core.getInput('provenance-output'), signedProvenanceOutput: core.getInput('signed-provenance-output'), + sourcePath: core.getInput('source-path'), + skipSourceTreeCheck: core.getBooleanInput( + 'skip-source-tree-check' + ), }, report: { reportJobSummary: core.getBooleanInput('report-job-summary'), @@ -229,6 +233,10 @@ async function run(config) { if (config.attest.signedProvenanceOutput !== '') args.push('--output-signed-prov', config.attest.signedProvenanceOutput); if (config.attest.signKey !== '') args.push('--key', config.attest.signKey); + if (config.attest.sourcePath !== '') + args.push('--source-path', config.attest.sourcePath); + if (config.attest.skipSourceTreeCheck) + args.push('--skip-source-tree-check'); if (config.cimon.clientId !== '') args.push('--client-id', config.cimon.clientId); if (config.cimon.secret !== '') args.push('--secret', config.cimon.secret);