scribe-security/Scribe SLSA Provanence evidence generator

Collect, Create and Store SLSA provenance evidence

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
targetTarget object name format=[<image:tag>, <dir path>, <git url>]yes
all-envAttach all environment variables
attest-configAttestation config path
attest-defaultAttestation default config, options=[sigstore sigstore-github x509 x509-env kms pubkey]
bomUpload SBOM evidence and by product
build-typeSet build type
builder-idSet builder id
by-productAttach by product path
cax509 CA Chain path
certx509 Cert path
componentsSelect by products components groups, options=[metadata layers packages syft files dep commits base_image]
crlx509 CRL path
crl-full-chainEnable Full chain CRL verfication
depthGit clone depth
disable-crlDisable certificate revocation verificatoin
externalAdd build external parameters
finished-onSet metadata finished time (YYYY-MM-DDThh:mm:ssZ)
forceForce overwrite cache
formatEvidence format, options=[statement attest]
git-authGit repository authentication info, [format: 'username:password']
git-branchGit branch in the repository
git-commitGit commit hash in the repository
git-tagGit tag in the repository
invocationSet metadata invocation ID
keyx509 Private key path
kmsProvide KMS key reference
ociEnable OCI store
oci-repoSelect OCI custom attestation repo
passPrivate key password
payloadpath of the decoded payload
platformSelect target platform, examples=windows/armv6, arm64 ..)
predicateImport predicate path
pubkeyPublic key path
skip-confirmationSkip Sigstore Confirmation
sourceGit repository source for target
source-asset-idSource asset id for Git source repo
source-asset-nameSource asset name for Git source repo
source-asset-platformSource asset platform for Git source repo
started-onSet metadata started time (YYYY-MM-DDThh:mm:ssZ)
statementImport statement path
cache-enableEnable local cache
configConfiguration file path
deliverableMark as deliverable, options=[true, false]
envEnvironment keys to include in evidence
gate-namePolicy Gate name
gate-typePolicy Gate type
inputInput Evidence target, format (\<parser>:\<file> or \<scheme>:\<name>:\<tag>)
labelAdd Custom labels
levelLog depth level, options=[panic fatal error warning info debug trace]
log-contextAttach context to all logs
log-fileOutput log to file
output-directoryOutput directory path./scribe/valint
output-fileOutput file name
pipeline-namePipeline name
predicate-typeCustom Predicate type (generic evidence format)
product-keyProduct Key
product-versionProduct Version
scribe-client-idScribe Client ID (deprecated)
scribe-client-secretScribe Client Token
scribe-disableDisable scribe client
scribe-enableEnable scribe client (deprecated)
scribe-urlScribe API Url
structuredEnable structured logger
timeoutTimeout duration
verboseLog verbosity level [-v,--verbose=1] = info, [-vv,--verbose=2] = debug
namedescription
OUTPUT_PATHevidence output file path