sabinghost19/ZTA Policy Attestor
Convert security-policy YAML to JSON and attach it as a Cosign attestation
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| image | Immutable image reference, recommended digest form ghcr.io/org/img@sha256:... | yes | — |
| policy-path | Path to security-policy.yaml | yes | — |
| manifest-dir | Optional directory containing GitOps manifests used to compute expected_infra_hash from ZeroTrustApplication spec | no | — |
| sync-manifest-image | When true and manifest-dir is set, compute expected_infra_hash using inputs.image as ZeroTrustApplication.spec.image | no | true |
| attestation-type | Cosign attestation type | no | https://devsecops.licenta.ro/attestations/custom-zta-policy/v1 |
Outputs
no outputs