scribe-security/Scribe SBOM evidence generator

Collect, Create and Store evidence for artifacts (SBOMs,SLSA provenance) or any third-party tools.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
targetTarget object name format=[<image:tag>, <dir path>, <git url>]yes
attach-regexAttach files content by regex
attest-configAttestation config path
attest-defaultAttestation default config, options=[sigstore sigstore-github x509 x509-env kms pubkey]
author-emailSet author email
author-nameSet author name
author-phoneSet author phone
base-imageBase image for the target
cax509 CA Chain path
certx509 Cert path
componentsSelect sbom components groups, options=[metadata layers packages syft files dep commits base_image]
crlx509 CRL path
crl-full-chainEnable Full chain CRL verfication
depthGit clone depth
disable-crlDisable certificate revocation verificatoin
filter-purlFilter out purls by regex
filter-regexFilter out files by regex
filter-scopeFilter packages by scope
forceForce overwrite cache
formatEvidence format, options=[json statement attest]
git-authGit repository authentication info, [format: 'username:password']
git-branchGit branch in the repository
git-commitGit commit hash in the repository
git-tagGit tag in the repository
keyx509 Private key path
kmsProvide KMS key reference
ociEnable OCI store
oci-repoSelect OCI custom attestation repo
package-exclude-typeExclude package type, options=[ruby python javascript java dpkg apk rpm go dotnet r rust binary sbom nix gem conan alpm cocoapods swift dart elixir php erlang github portage haskell kernel wordpress lua bitnami terraform]
package-groupSelect package group, options=[index install all]
package-typeSelect package type, options=[ruby python javascript java dpkg apk rpm go dotnet r rust binary sbom nix gem conan alpm cocoapods swift dart elixir php erlang github portage haskell kernel wordpress lua bitnami terraform]
passPrivate key password
payloadpath of the decoded payload
platformSelect target platform, examples=windows/armv6, arm64 ..)
provenanceInclude SLSA Provenance evidence
pubkeyPublic key path
skip-confirmationSkip Sigstore Confirmation
supplier-emailSet supplier email
supplier-nameSet supplier name
supplier-phoneSet supplier phone
supplier-urlSet supplier url
cache-enableEnable local cache
configConfiguration file path
deliverableMark as deliverable, options=[true, false]
envEnvironment keys to include in evidence
gate-namePolicy Gate name
gate-typePolicy Gate type
inputInput Evidence target, format (\<parser>:\<file> or \<scheme>:\<name>:\<tag>)
labelAdd Custom labels
levelLog depth level, options=[panic fatal error warning info debug trace]
log-contextAttach context to all logs
log-fileOutput log to file
output-directoryOutput directory path./scribe/valint
output-fileOutput file name
pipeline-namePipeline name
predicate-typeCustom Predicate type (generic evidence format)
product-keyProduct Key
product-versionProduct Version
scribe-client-idScribe Client ID (deprecated)
scribe-client-secretScribe Client Token
scribe-disableDisable scribe client
scribe-enableEnable scribe client (deprecated)
scribe-urlScribe API Url
structuredEnable structured logger
timeoutTimeout duration
verboseLog verbosity level [-v,--verbose=1] = info, [-vv,--verbose=2] = debug
namedescription
OUTPUT_PATHevidence output file path