colek42/witness-run

Creates Attestation of CI Process with Witness

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
action-refReference to a GitHub Action to run (format: owner/repo@ref). If provided, command is ignored.no
commandcommand to run (not needed if action-ref is provided)no
stepName of the step being runyes
witness_versionVersion of Witness CLIno0.8.1
witness-argsAdditional command-line arguments to pass to Witness (space-separated). Useful for undocumented or future options not yet supported explicitly by this action.no
outfileFile to which to write signed datano
witness_traceEnable tracing for the commandnofalse
workingdirDirectory from which commands will runno
attestationsAttestations to record ('product' and 'material' are always recorded)noenvironment git github
enable-archivistaUse Archivista to store or retrieve attestationsnotrue
archivista-serverURL of the Archivista server to store or retrieve attestationsnohttps://archivista.testifysec.io
attestor-link-exportExport the Link predicate in its own attestationnofalse
attestor-maven-pom-pathPath to the Maven POM fileno
attestor-sbom-exportExport the SBOM predicate in its own attestationnofalse
attestor-slsa-exportExport the SLSA provenance predicate in its own attestationnofalse
product-exclude-globPattern to use when recording products. Files that match this pattern will be excluded as subjects on the attestation.no
product-include-globPattern to use when recording products. Files that match this pattern will be included as subjects on the attestation.no*
enable-sigstoreUse Sigstore for attestationnotrue
fulcioFulcio address to sign withno
fulcio-oidc-client-idOIDC client ID to use for authenticationno
fulcio-oidc-issuerOIDC issuer to use for authenticationno
fulcio-oidc-redirect-urlOIDC redirect URL (Optional). The default oidc-redirect-url is 'http://localhost:0/auth/callback'no
fulcio-tokenRaw token string to use for authentication to fulciono
fulcio-token-pathPath to the file containing a raw token to use for authentication to fulciono
certificatePath to the signing key's certificateno
keyPath to the signing keyno
intermediatesIntermediates that link trust back to a root of trust in the policyno
kms-aws-config-fileThe shared configuration file to use with the AWS KMS signer providerno
kms-aws-credentials-fileThe shared credentials file to use with the AWS KMS signer providerno
kms-aws-insecure-skip-verifySkip verification of the server's certificate chain and host namenofalse
kms-aws-profileThe shared configuration profile to use with the AWS KMS signer providerno
kms-aws-remote-verifyVerify signature using AWS KMS remote verification. If false, the public key will be pulled from AWS KMS and verification will take place locallynotrue
kms-gcp-credentials-fileThe credentials file to use with the GCP KMS signer providerno
kms-hash-typeThe hash type to use for signingnosha256
kms-key-versionThe key version to use for signingno
kms-refThe KMS Reference URI to use for connecting to the KMS serviceno
spiffe-socketPath to the SPIFFE Workload API socketno
vault-altnamesAlt names to use for the generated certificate. All alt names must be allowed by the vault role policyno
vault-commonnameCommon name to use for the generated certificate. Must be allowed by the vault role policyno
vault-namespaceVault namespace to useno
vault-pki-secrets-engine-pathPath to the Vault PKI Secrets Engine to usenopki
vault-roleName of the Vault role to generate the certificate forno
vault-tokenToken to use to connect to Vaultno
vault-ttlTime to live for the generated certificate. Defaults to the vault role policy's configured TTL if not providedno
vault-urlBase url of the Vault instance to connect tono
timestamp-serversTimestamp Authority Servers to use when signing envelopeno
hashesHashes selected for digest calculation (space separated)nosha256
env-add-sensitive-keyAdd keys or globs (e.g. '*TEXT') to the list of sensitive environment keysno
env-disable-default-sensitive-varsDisable the default list of sensitive vars and only use the items mentioned by --add-sensitive-keynofalse
env-exclude-sensitive-keyExclude specific keys from the list of sensitive environment keys. Does not support globsno
env-filter-sensitive-varsSwitch from obfuscate to filtering variables which removes them from the output completelynofalse
dirhash-globDirhash glob can be used to collapse material and product hashes on matching directory matchesno
*Any other inputno

no outputs