Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions attest/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,8 @@ See the inputs section below for the full list.
| Name | Description | Default |
|---|---|---|
| `subjects` | Whitespace-separated list of artifact paths or base64 subjects | — |
| `source-path` | Path to the source checkout recorded in the attestation. Unset means automatic discovery (subject paths, run-id directory, workspace). Requires cimon v1.0.24 or later | — |
| `skip-source-tree-check` | Skip verifying the source tree matches the recorded commit | `false` |
| `sign-key` | Path to a private ECDSA/RSA/ED25519 PEM key | — |
| `keyless` | Use keyless (Sigstore) signing | `false` |
| `tlog-upload` | Upload signature to Rekor transparency log | `true` |
Expand Down
13 changes: 13 additions & 0 deletions attest/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,19 @@ inputs:
description: A white space seperated list of paths, or base64-encoded subjects. Each path can be file, directory or image reference
required: false
default: ''
source-path:
description: |
Path to the source checkout recorded in the attestation's
resolvedDependencies. When unset, cimon discovers the source
automatically: from the subject paths, a directory named after the
CI run id, or the workspace. Set this when the source is checked
out to a location discovery cannot reach.
required: false
default: ''
skip-source-tree-check:
description: Skip verifying that the source working tree matches the recorded commit (faster on very large trees)
required: false
default: 'false'
image-ref:
description: (deprecated) The container reference to generate provenance for. Either subjects or imageRef are required
required: false
Expand Down
8 changes: 8 additions & 0 deletions attest/dist/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -127702,6 +127702,10 @@ function getActionConfig() {
),
provenanceOutput: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getInput('provenance-output'),
signedProvenanceOutput: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getInput('signed-provenance-output'),
sourcePath: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getInput('source-path'),
skipSourceTreeCheck: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getBooleanInput(
'skip-source-tree-check'
),
},
report: {
reportJobSummary: _actions_core__WEBPACK_IMPORTED_MODULE_0__.getBooleanInput('report-job-summary'),
Expand Down Expand Up @@ -127789,6 +127793,10 @@ async function run(config) {
if (config.attest.signedProvenanceOutput !== '')
args.push('--output-signed-prov', config.attest.signedProvenanceOutput);
if (config.attest.signKey !== '') args.push('--key', config.attest.signKey);
if (config.attest.sourcePath !== '')
args.push('--source-path', config.attest.sourcePath);
if (config.attest.skipSourceTreeCheck)
args.push('--skip-source-tree-check');
if (config.cimon.clientId !== '')
args.push('--client-id', config.cimon.clientId);
if (config.cimon.secret !== '') args.push('--secret', config.cimon.secret);
Expand Down
8 changes: 8 additions & 0 deletions attest/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,10 @@ function getActionConfig() {
),
provenanceOutput: core.getInput('provenance-output'),
signedProvenanceOutput: core.getInput('signed-provenance-output'),
sourcePath: core.getInput('source-path'),
skipSourceTreeCheck: core.getBooleanInput(
'skip-source-tree-check'
),
},
report: {
reportJobSummary: core.getBooleanInput('report-job-summary'),
Expand Down Expand Up @@ -229,6 +233,10 @@ async function run(config) {
if (config.attest.signedProvenanceOutput !== '')
args.push('--output-signed-prov', config.attest.signedProvenanceOutput);
if (config.attest.signKey !== '') args.push('--key', config.attest.signKey);
if (config.attest.sourcePath !== '')
args.push('--source-path', config.attest.sourcePath);
if (config.attest.skipSourceTreeCheck)
args.push('--skip-source-tree-check');
if (config.cimon.clientId !== '')
args.push('--client-id', config.cimon.clientId);
if (config.cimon.secret !== '') args.push('--secret', config.cimon.secret);
Expand Down
Loading