sabinghost19/VBBI Voucher Attestor

Generate a Voucher-Based Build Integrity predicate and attach it as a Cosign attestation

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
imageImmutable image reference in digest formyes
commit-shaGit commit SHA associated with the buildyes
step-spec-pathPath to a JSON file containing the ordered list of VBBI steps and metadata filesyes
hmac-keyShared HMAC key used to seal the voucher in this stagenodev-only-vbbi-key
vault-addressVault base URL used for Transit HMAC generationno""
vault-tokenVault token used to access Transit when vault-address is configuredno""
vault-namespaceOptional Vault enterprise namespaceno""
vault-transit-mountVault Transit mount pathnotransit
vault-transit-keyVault Transit key name used to compute the VBBI HMAC chainno""
vault-transit-algorithmVault Transit HMAC algorithmnosha2-256
slsa-levelSLSA level declared in the voucher build contextno3
attestation-typeCosign attestation type for the VBBI vouchernohttps://devsecops.licenta.ro/VBBI/v1
namedescription
merkle-rootComputed Merkle root for the generated VBBI voucher
predicate-pathPath to the generated VBBI predicate JSON file