carabiner-dev/Verify AMPEL Policy

Verifies a software artifact against an 🔴🟡🟢 AMPEL supply chain policy

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
policyPath or URI to the security policy file to evaluate againstyes
subjectPath to a file or hash (algo:value) to use as verification subjectyes
collectorCollector to load to read attestationsyes
attestAttest the policy evaluation resultsnotrue
attest-formatFormat of the results attestationnoampel
results-pathPath to store the results attestationnoampel.intoto.json
push-attestationPushes the attestation to the GitHub attestations storenofalse
attestationComma separated list of attestations to ingestno""
signerComma separated list of signer identity slugsno""
keyPath to a key file to use for verificationno""
keydataRaw key material to use for verificationno""
contextContextual values to pass to the policy (e.g. "key=value,key2=value2")no""
failFail the workflow if the policy failsnotrue

no outputs