Skip to main content

SignVerifyConfig

Struct SignVerifyConfig 

Source
pub struct SignVerifyConfig {
    pub enabled: Option<bool>,
    pub certificate_identity: Option<String>,
    pub certificate_identity_regexp: Option<String>,
    pub certificate_oidc_issuer: Option<String>,
}
Expand description

Post-sign verification settings shared by SignConfig and DockerSignConfig.

After each signature is produced, the sign stage re-verifies it with the matching verifier (cosign verify-blob for detached cosign signatures, cosign verify for registry-attached docker signatures, gpg --verify for gpg) so “the signer exited 0” is upgraded to “the signature actually verifies”. Everything is derived when possible:

  • keyed cosign — the public key is derived once per run via cosign public-key --key <ref>; nothing to configure.
  • keyless cosign — the certificate identity/issuer are derived from the ambient GitHub Actions OIDC environment (GITHUB_SERVER_URL/GITHUB_WORKFLOW_REF); outside GitHub Actions, supply them here or verification skips with a named reason.
  • gpg — verified against the same keyring that signed.
signs:
  - cmd: cosign
    args: ["sign-blob", "--bundle={{ Signature }}", "--yes", "{{ Artifact }}"]
    verify:
      certificate_identity: "https://github.com/acme/app/.github/workflows/release.yml@refs/tags/v1.0.0"
      certificate_oidc_issuer: "https://token.actions.githubusercontent.com"

Fields§

§enabled: Option<bool>

Whether to verify each produced signature (default: true).

§certificate_identity: Option<String>

Exact certificate identity (SAN) expected in a keyless signing certificate (cosign --certificate-identity). Overrides the value derived from the GitHub Actions environment.

§certificate_identity_regexp: Option<String>

Regular expression matched against the keyless certificate identity (cosign --certificate-identity-regexp). Ignored when certificate_identity is set.

§certificate_oidc_issuer: Option<String>

Expected OIDC issuer of the keyless signing certificate (cosign --certificate-oidc-issuer). Overrides the derived GitHub Actions issuer.

Implementations§

Source§

impl SignVerifyConfig

Source

pub fn is_enabled(&self) -> bool

Whether verification is enabled (default: true).

Trait Implementations§

Source§

impl Clone for SignVerifyConfig

Source§

fn clone(&self) -> SignVerifyConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SignVerifyConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for SignVerifyConfig

Source§

fn default() -> SignVerifyConfig

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for SignVerifyConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl JsonSchema for SignVerifyConfig

Source§

fn schema_name() -> Cow<'static, str>

The name of the generated JSON Schema. Read more
Source§

fn schema_id() -> Cow<'static, str>

Returns a string that uniquely identifies the schema produced by this type. Read more
Source§

fn json_schema(generator: &mut SchemaGenerator) -> Schema

Generates a JSON Schema for this type. Read more
Source§

fn inline_schema() -> bool

Whether JSON Schemas generated for this type should be included directly in parent schemas, rather than being re-used where possible using the $ref keyword. Read more
Source§

impl Serialize for SignVerifyConfig

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more