Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 17 additions & 7 deletions attest/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,23 @@ If your environment cannot submit to the public Sigstore transparency
log (e.g. customers in the USA / EU with data-residency requirements),
use one of:

- **KMS signing**: `--kms vault://<key-id>` (HashiCorp Vault transit) or
`--kms awskms://<arn>` (AWS KMS) — signature stays in your control.
- **KMS signing**: `--kms vault://<key-id>` (HashiCorp Vault transit).
The signature stays in your control. Vault transit is the only KMS
backend implemented today.
- **Keyed signing with checked-in private key**: `sign-key: private-key.pem`.
- **Private Sigstore**: deploy your own Fulcio + Rekor and pass
`fulcio-server-url` + `rekor-server-url`.

See the inputs section below for the full list.

> **RFC 3161 timestamping is not available with keyed or KMS signing.**
> `include-timestamp` and `timestamp-server-url` are forwarded to the
> CLI only when `keyless: true`, and the CLI itself applies timestamping
> only in keyless mode. A signature produced with `sign-key` or a KMS
> provider carries no timestamp, so it has no time anchor proving it was
> made before the key was rotated or compromised. This is a known gap
> and we intend to close it.

## Inputs

| Name | Description | Default |
Expand All @@ -64,11 +73,12 @@ See the inputs section below for the full list.
| `skip-source-tree-check` | Skip verifying the source tree matches the recorded commit | `false` |
| `sign-key` | Path to a private ECDSA/RSA/ED25519 PEM key | — |
| `keyless` | Use keyless (Sigstore) signing | `false` |
| `tlog-upload` | Upload signature to Rekor transparency log | `true` |
| `fulcio-server-url` | Fulcio server URL | `https://fulcio.sigstore.dev` |
| `rekor-server-url` | Rekor server URL | `https://rekor.sigstore.dev` |
| `timestamp-server-url` | RFC3161 timestamp server URL | — |
| `allow-submit-data-to-public-sigstore` | Required when using public Sigstore | `false` |
| `tlog-upload` | **Keyless only.** Upload signature to Rekor transparency log | `true` |
| `include-timestamp` | **Keyless only.** Request an RFC 3161 timestamp and embed it in the signature | `false` |
| `fulcio-server-url` | **Keyless only.** Fulcio server URL | `https://fulcio.sigstore.dev` |
| `rekor-server-url` | **Keyless only.** Rekor server URL | `https://rekor.sigstore.dev` |
| `timestamp-server-url` | **Keyless only.** RFC3161 timestamp server URL. Not forwarded to the CLI unless `keyless: true` | — |
| `allow-submit-data-to-public-sigstore` | **Keyless only.** Required when using public Sigstore | `false` |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Mark the consent input as keyless-only in action metadata

This table now correctly identifies allow-submit-data-to-public-sigstore as keyless-only, but its corresponding attest/action.yml description remains unchanged and does not say that the input is ignored otherwise. Since the Actions UI presents action.yml, users configuring the action there can still assume this input affects keyed signing even though attest/index.js only forwards it inside the keyless branch; update that metadata description consistently with the other keyless-only inputs.

Useful? React with 👍 / 👎.

| `provenance-output` | Path for unsigned provenance | `provenance.intoto.jsonl` |
| `signed-provenance-output` | Path for signed provenance | `provenance.intoto.jsonl.sig` |
| `report-job-summary` | Render provenance in the workflow job summary | `true` |
Expand Down
10 changes: 5 additions & 5 deletions attest/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,23 +48,23 @@ inputs:
required: false
default: 'false'
tlog-upload:
description: Allow the creation of a Rekor transparency log (TLog) entry.
description: 'Keyless signing only: allow the creation of a Rekor transparency log (TLog) entry. Ignored unless keyless is true.'
required: false
default: 'true'
include-timestamp:
description: Allow timestamping of the artifact signature against a timestamping authority.
description: 'Keyless signing only: allow RFC 3161 timestamping of the artifact signature against a timestamping authority. Ignored unless keyless is true.'
required: false
default: 'false'
fulcio-server-url:
description: Fulcio server URL
description: 'Keyless signing only: Fulcio server URL'
required: false
default: 'https://fulcio.sigstore.dev'
rekor-server-url:
description: Rekor server URL
description: 'Keyless signing only: Rekor server URL'
required: false
default: 'https://rekor.sigstore.dev'
timestamp-server-url:
description: Timestamp server URL
description: 'Keyless signing only: timestamp server URL. Not forwarded to the CLI unless keyless is true.'
required: false
allow-submit-data-to-public-sigstore:
description: Agree to submit data to an immutable public transparency log (Needed for public Sigstore)
Expand Down
Loading