Skip to main content

vgi_core/
lib.rs

1//! Shared primitives for Verifiable Git Infrastructure (VGI).
2//!
3//! Pure, dependency-light building blocks that both the signer
4//! (`did-git-sign`) and the CI verifier (`verify-trust`) rely on, kept in one
5//! crate so their wire formats cannot drift:
6//!
7//! - the PROTOCOL.sshsig encoder ([`create_ssh_signature`]) and the git
8//!   sshsig namespace ([`GIT_SSHSIG_NAMESPACE`]),
9//! - git commit-object handling ([`split_signed_commit`],
10//!   [`normalize_sshsig_armor`], [`committer_did`]),
11//! - DID-document Ed25519 key extraction ([`ed25519_signing_keys_from_doc`])
12//!   and service discovery ([`registry_referral`], [`messaging_mediator`]),
13//! - the forge-qualified resource grammar ([`normalize_resource`],
14//!   [`resource_contains`]) that the verifier, the VTC projection and the
15//!   forge adapters must all agree on byte for byte.
16//!
17//! Nothing here touches the network, a keyring, or a VTA — that is what lets
18//! the CI verifier stay a small, fast dependency.
19
20mod commit;
21mod did;
22pub mod resource;
23mod services;
24mod sshsig;
25
26pub use commit::{
27    committer_did, committer_identity, conflicting_signer_dids, normalize_sshsig_armor, signer_did,
28    split_signed_commit,
29};
30pub use did::{ED25519_MULTICODEC_PREFIX, ed25519_signing_keys_from_doc};
31pub use resource::{
32    ResourceError, ResourceErrorKind, normalize_resource, normalize_resource_with_depth,
33    resource_contains,
34};
35pub use services::{messaging_mediator, registry_referral};
36pub use sshsig::{
37    GIT_SSHSIG_NAMESPACE, assemble_ssh_signature, create_ssh_signature, sshsig_message_hash,
38    sshsig_signed_data,
39};