testifysec/TestifySec Action Wrapper with Witness

Downloads and executes another GitHub Action or direct command with Witness attestation for supply chain security

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
action-refReference to the nested action (e.g., owner/repo@ref or owner/repo@v1)no
commandCommand to run with Witness (use this or action-ref)no
witness-versionVersion of Witness to use (check https://github.com/testifysec/witness/releases for valid versions)no0.8.1
witness-install-dirDirectory to install Witnessno./
stepStep name for the attestationyes
attestationsSpace-separated list of attestors to runyes
outfilePath to output file for the attestationno
enable-archivistaEnable archivista for storing attestationsnofalse
archivista-serverArchivista server URLno
certificatePath to certificate fileno
keyPath to key fileno
intermediatesSpace-separated list of intermediate certificate pathsno""
enable-sigstoreEnable sigstore for signingnofalse
fulcioFulcio URLno
fulcio-oidc-client-idFulcio OIDC client IDno
fulcio-oidc-issuerFulcio OIDC issuerno
fulcio-tokenFulcio tokenno
timestamp-serversSpace-separated list of timestamp server URLsno""
traceEnable tracingno
spiffe-socketPath to SPIFFE socketno
product-exclude-globGlob pattern for excluding productsno
product-include-globGlob pattern for including productsno
attestor-link-exportExport link attestornofalse
attestor-sbom-exportExport SBOM attestornofalse
attestor-slsa-exportExport SLSA attestornofalse
attestor-maven-pom-pathPath to Maven POM fileno
who-to-greetWho to greetnoWorld
namedescription
git_oidGitOID of the attestation (if created)