testifysec/witness-run

Creates Attestation of CI Process with Witness

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
witness-install-dirDirectory to install witness in. The directory will be created if it does not existno
archivista-serverURL of the Archivista server to store or retrieve attestationsnohttps://archivista.testifysec.io
archivista-headersHeaders to include when making requests to Archivista. Input is expected to be new line separatedno""
attestationsAttestations to recordnoenvironment git github
attestor-link-exportExport the attestor link predicate in its own attestationnofalse
attestor-maven-pom-pathPath to the Maven POM fileno
attestor-sbom-exportExport the SBOM predicate in its own attestationnofalse
attestor-slsa-exportExport the SLSA predicate in its own attestationnofalse
enable-sigstoreUse Sigstore for attestationnotrue
commandcommand to runyes
certificatePath to the signing key's certificateno
enable-archivistaUse Archivista to store or retrieve attestationsnotrue
fulcioFulcio address to sign withno
fulcio-oidc-client-idOIDC client ID to use for authenticationno
fulcio-oidc-issuerOIDC issuer to use for authenticationno
fulcio-tokenRaw token to use for authenticationno
intermediatesIntermediates that link trust back to a root of trust in the policyno
keyPath to the signing keyno
outfileFile to which to write signed data. Defaults to stdoutno
product-exclude-globPattern to use when recording products. Files that match this pattern will be excluded as subjects on the attestation.no
product-include-globPattern to use when recording products. Files that match this pattern will be included as subjects on the attestation.no
spiffe-socketPath to the SPIFFE Workload API socketno
stepName of the step being runyes
timestamp-serversTimestamp Authority Servers to use when signing envelopeno
traceEnable tracing for the commandnofalse
versionVersion of Witness CLIno0.9.2
workingdirDirectory from which commands will runno

no outputs