Skip to main content

Module attestation

Module attestation 

Source

Structs§

CertificateInfo
GhAttestationOutput
Raw JSON structure from gh attestation verify --format json
GhVerificationResult
SignatureInfo
Statement
StatementSubject
An in-toto statement subject entry.

Functions§

collect_release_attestations
Download release assets to a temporary directory, verify attestations for each, and return an EvidenceState suitable for EvidenceBundle.artifact_attestations.
to_artifact_attestations
Convert parsed gh attestation verify results into core evidence types.
verify_artifact
Verify an artifact using gh attestation verify and return parsed results.