cosign
aqua > v1.26.0
Please see Cosign and SLSA Provenance Support too.
Fields
- opts ([]string): cosign verify-blob options
- signature
- type (string):
github_release,http,forgejo_release,gitea_releaseorgitlab_release - repo_owner (string) (optional):
- repo_name (string) (optional):
- url (string) (
httprequires): - asset (string) (every type but
httprequires):
- type (string):
- key
- same as
signature
- same as
- certificate
- same as
signature
- same as
- bundle (
aqua >= v2.47.0)- same as
signature
- same as
- certificate_identity (string):
aqua >= v2.65.0 - certificate_identity_regexp (string):
aqua >= v2.65.0 - certificate_oidc_issuer (string):
aqua >= v2.65.0 - certificate_github_workflow_repository (string):
aqua >= v2.65.0 - certificate_github_workflow_ref (string):
aqua >= v2.65.0
e.g.
cosign:
opts:
- --signature
- https://github.com/terraform-linters/tflint/releases/download/{{.Version}}/checksums.txt.keyless.sig
- --certificate
- https://github.com/terraform-linters/tflint/releases/download/{{.Version}}/checksums.txt.pem
cosign:
signature:
type: github_release
asset: checksums.txt.keyless.sig
certificate:
type: github_release
asset: checksums.txt.pem
Certificate fields
The fields added in v2.65.0 are passed to cosign verify-blob as the flag of the same name, after opts, and only when they are set. They are templates like opts, so a field can name every version's identity.
| field | flag |
|---|---|
| certificate_identity | --certificate-identity |
| certificate_identity_regexp | --certificate-identity-regexp |
| certificate_oidc_issuer | --certificate-oidc-issuer |
| certificate_github_workflow_repository | --certificate-github-workflow-repository |
| certificate_github_workflow_ref | --certificate-github-workflow-ref |
They say what opts can say too, but as fields, so what is verified can be read without parsing a command line. A flag shouldn't be given both ways.
cosign:
bundle:
type: github_release
asset: "{{.Asset}}.sigstore.json"
certificate_identity: https://github.com/foundry-rs/foundry/.github/workflows/release.yml@refs/tags/{{.Version}}
certificate_oidc_issuer: https://token.actions.githubusercontent.com