1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2024-12-14 11:57:48 +00:00
kyverno/pkg/images/verifier.go
Vishal Choudhary 06ffd1c961
feat: add support for sigstore bundle verification (#10567)
* feat: add support for sigstore bundle verification

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>

* fix: missed change

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>

* fix: ci

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>

* fix: linter

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>

* fix: another linter

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>

* fix: add size check in layer

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>

---------

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>
Co-authored-by: shuting <shuting@nirmata.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2024-08-16 11:36:48 +00:00

55 lines
1.5 KiB
Go

package images
import (
"context"
"github.com/google/go-containerregistry/pkg/authn"
gcrremote "github.com/google/go-containerregistry/pkg/v1/remote"
)
type ImageVerifier interface {
// VerifySignature verifies that the image has the expected signatures
VerifySignature(ctx context.Context, opts Options) (*Response, error)
// FetchAttestations retrieves signed attestations and decodes them into in-toto statements
// https://github.com/in-toto/attestation/blob/main/spec/README.md#statement
FetchAttestations(ctx context.Context, opts Options) (*Response, error)
}
type Client interface {
Keychain() authn.Keychain
Options(context.Context) ([]gcrremote.Option, error)
}
type Options struct {
SigstoreBundle bool
ImageRef string
Client Client
FetchAttestations bool
Key string
Cert string
CertChain string
Roots string
Subject string
SubjectRegExp string
Issuer string
IssuerRegExp string
AdditionalExtensions map[string]string
Annotations map[string]string
Repository string
CosignOCI11 bool
IgnoreTlog bool
RekorURL string
RekorPubKey string
IgnoreSCT bool
TSACertChain string
CTLogsPubKey string
SignatureAlgorithm string
PredicateType string
Type string
Identities string
}
type Response struct {
Digest string
Statements []map[string]interface{}
}