Paquet : sigstore-go (0.7.1-2 et autres)
Liens pour sigstore-go
Ressources Debian :
- Rapports de bogues
- Developer Information
- Journal des modifications Debian
- Fichier de licence
- Suivis des correctifs pour Debian
Télécharger le paquet source sigstore-go :
Responsables :
Ressources externes :
- Page d'accueil [github.com]
Paquets similaires :
Sigstore signing and verification (program)
A client library for Sigstore (https://www.sigstore.dev/), written in Go. Features:
* Signing and verification of Sigstore bundles (https://github.com/sigstore/protobuf- specs/blob/main/protos/sigstore_bundle.proto) compliant with Sigstore Client Spec * Verification of raw Sigstore signatures by creating bundles for them (see conformance tests (/cmd/conformance/main.go) for example) * Signing and verifying with a Timestamp Authority (TSA) * Signing and verifying (offline or online) with Rekor (Artifact Transparency Log) * Structured verification results including certificate metadata * TUF support * Verification support for custom trusted root (https://github.com/sigstore/protobuf- specs/blob/main/protos/sigstore_trustroot.proto) * Basic CLI and examples
For an example of how to use this library, see the verification documentation (/docs/verification.md), the CLI cmd/sigstore-go (/cmd/sigstore-go/main.go). Note that the CLI is to demonstrate how to use the library, and not intended as a fully- featured Sigstore CLI like cosign (https://github.com/sigstore/cosign).
Background
Sigstore already has a canonical Go client implementation, cosign (https://github.com/sigstore/cosign), which was developed with a focus on container image signing/verification. It has a rich CLI and a long legacy of features and development. sigstore-go is a more minimal and friendly API for integrating Go code with Sigstore, with a focus on the newly specified data structures in sigstore/protobuf-specs (https://github.com/sigstore/protobuf-specs). sigstore-go attempts to minimize the dependency tree for simple signing and verification tasks, omitting KMS support and container image verification.
This package contains the binaries.
Autres paquets associés à sigstore-go
|
|
|
|
-
- dep: libc6 (>= 2.34) [non loong64]
- bibliothèque C GNU : bibliothèques partagées
un paquet virtuel est également fourni par libc6-udeb
- dep: libc6 (>= 2.41) [loong64]
Télécharger sigstore-go
Architecture | Version | Taille du paquet | Espace occupé une fois installé | Fichiers |
---|---|---|---|---|
amd64 | 0.7.1-2+b4 | 12 703,7 ko | 44 093,0 ko | [liste des fichiers] |
arm64 | 0.7.1-2+b4 | 10 858,3 ko | 41 615,0 ko | [liste des fichiers] |
armel | 0.7.1-2+b4 | 11 051,0 ko | 42 078,0 ko | [liste des fichiers] |
armhf | 0.7.1-2+b4 | 11 039,9 ko | 41 886,0 ko | [liste des fichiers] |
i386 | 0.7.1-2+b4 | 11 902,9 ko | 41 965,0 ko | [liste des fichiers] |
loong64 (portage non officiel) | 0.7.1-2 | 11 126,9 ko | 42 313,0 ko | [liste des fichiers] |
mips64el | 0.7.1-2+b4 | 9 951,5 ko | 48 134,0 ko | [liste des fichiers] |
ppc64el | 0.7.1-2+b4 | 10 720,6 ko | 43 277,0 ko | [liste des fichiers] |
riscv64 | 0.7.1-2+b4 | 11 233,7 ko | 41 933,0 ko | [liste des fichiers] |
s390x | 0.7.1-2+b4 | 11 405,0 ko | 46 541,0 ko | [liste des fichiers] |