├── .clomonitor.yml ├── .github ├── ISSUE_TEMPLATE │ ├── bug-report.md │ └── feature-request.md ├── PULL_REQUEST_TEMPLATE.md ├── dependabot.yml └── workflows │ ├── codeql.yml │ ├── dependency-review.yml │ ├── fossa.yml │ ├── golangci-lint.yml │ ├── release.yml │ ├── scorecard.yml │ ├── verify-docgen.yml │ ├── verify-licence.yml │ └── witness.yml ├── .gitignore ├── .gitlab-ci.yml ├── .goreleaser.yaml ├── .pre-commit-config.yaml ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md ├── DEPENDENCY.md ├── GOVERNANCE.md ├── INSTALL.md ├── LICENSE ├── MAINTAINERS.md ├── Makefile ├── README.md ├── SECURITY-INSIGHTS.yml ├── SECURITY.md ├── arch.drawio.png ├── cmd ├── attestors.go ├── attestors_test.go ├── completion.go ├── completion_test.go ├── config.go ├── keyloader.go ├── log.go ├── log_test.go ├── policy.go ├── policy_check.go ├── root.go ├── root_test.go ├── run.go ├── run_test.go ├── sign.go ├── sign_test.go ├── verify.go ├── verify_test.go ├── version.go └── version_test.go ├── dev ├── .dockerignore ├── Dockerfile.go-builder └── build-and-push-builders.sh ├── docgen ├── docs.go └── verify.sh ├── docs-website ├── .env ├── README.md ├── babel.config.js ├── docusaurus.config.js ├── package.json ├── sidebars.js ├── src │ ├── components │ │ └── HomepageFeatures │ │ │ ├── index.js │ │ │ └── styles.module.css │ ├── css │ │ └── custom.css │ └── pages │ │ ├── index.js │ │ └── index.module.css ├── static │ ├── .nojekyll │ └── img │ │ ├── favicon.ico │ │ ├── logo.png │ │ ├── logo.svg │ │ ├── undraw_alert_re_j2op.svg │ │ ├── undraw_certificate_re_yadi.svg │ │ ├── undraw_hacker_mind_-6-y85.svg │ │ ├── undraw_programmer_re_owql.svg │ │ └── witness-og.png └── yarn.lock ├── docs ├── about │ └── how-witness-works.md ├── assets │ ├── arch.drawio.png │ ├── attestation.png │ ├── demo.gif │ ├── logo.png │ └── verification.png ├── attestors │ ├── aws-codebuild.json │ ├── aws-codebuild.md │ ├── aws.json │ ├── aws.md │ ├── command-run.json │ ├── command-run.md │ ├── docker.json │ ├── docker.md │ ├── environment.json │ ├── environment.md │ ├── gcp-iit.json │ ├── gcp-iit.md │ ├── git.json │ ├── git.md │ ├── github.json │ ├── github.md │ ├── gitlab.json │ ├── gitlab.md │ ├── jenkins.json │ ├── jenkins.md │ ├── json.jsx │ ├── jwt.json │ ├── jwt.md │ ├── k8smanifest.json │ ├── k8smanifest.md │ ├── link.json │ ├── link.md │ ├── lockfiles.json │ ├── lockfiles.md │ ├── material.json │ ├── material.md │ ├── maven.json │ ├── maven.md │ ├── oci.json │ ├── oci.md │ ├── omnitrail.json │ ├── omnitrail.md │ ├── policyverify.json │ ├── policyverify.md │ ├── product.json │ ├── product.md │ ├── sarif.json │ ├── sarif.md │ ├── sbom.json │ ├── sbom.md │ ├── secretscan.json │ ├── secretscan.md │ ├── slsa.json │ ├── slsa.md │ ├── system-packages.json │ ├── system-packages.md │ ├── vex.json │ └── vex.md ├── commands.md ├── concepts │ ├── attestor.md │ ├── collection.md │ ├── config.md │ └── policy.md ├── signers │ └── kms.md └── tutorials │ ├── artifact-policy.md │ ├── getting-started.md │ └── sigstore-keyless.md ├── go.mod ├── go.sum ├── install-witness.sh ├── internal └── policy │ ├── policy.go │ └── policy_test.go ├── main.go ├── netlify.toml ├── options ├── options.go ├── root.go ├── root_test.go ├── run.go ├── run_test.go ├── sign.go ├── sign_test.go ├── signers.go ├── verifiers.go ├── verify.go └── verify_test.go └── test ├── .gitignore ├── cdx-att.json ├── cdx-sbom-policy-signed.json ├── cdx-sbom-policy.json ├── common.sh ├── failkey.pem ├── freetsa.pem ├── fulcio-policy-signed.json ├── main.go ├── policy-hello-signed.json ├── policy.json ├── sbom-policy-signed.json ├── sbom.cdx.json ├── sbom.spdx.json ├── spdx-att.json ├── spdx-sbom-policy-signed.json ├── spdx-sbom-policy.json ├── test-mac.yaml ├── test-oci.sh ├── test.json ├── test.sh ├── test.txt ├── test.yaml ├── testkey.pem ├── testkey2.pem ├── testpub.pem └── testpub2.pem /.clomonitor.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.clomonitor.yml -------------------------------------------------------------------------------- /.github/ISSUE_TEMPLATE/bug-report.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/ISSUE_TEMPLATE/bug-report.md -------------------------------------------------------------------------------- /.github/ISSUE_TEMPLATE/feature-request.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/ISSUE_TEMPLATE/feature-request.md -------------------------------------------------------------------------------- /.github/PULL_REQUEST_TEMPLATE.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/PULL_REQUEST_TEMPLATE.md -------------------------------------------------------------------------------- /.github/dependabot.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/dependabot.yml -------------------------------------------------------------------------------- /.github/workflows/codeql.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/codeql.yml -------------------------------------------------------------------------------- /.github/workflows/dependency-review.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/dependency-review.yml -------------------------------------------------------------------------------- /.github/workflows/fossa.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/fossa.yml -------------------------------------------------------------------------------- /.github/workflows/golangci-lint.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/golangci-lint.yml -------------------------------------------------------------------------------- /.github/workflows/release.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/release.yml -------------------------------------------------------------------------------- /.github/workflows/scorecard.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/scorecard.yml -------------------------------------------------------------------------------- /.github/workflows/verify-docgen.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/verify-docgen.yml -------------------------------------------------------------------------------- /.github/workflows/verify-licence.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/verify-licence.yml -------------------------------------------------------------------------------- /.github/workflows/witness.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.github/workflows/witness.yml -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.gitignore -------------------------------------------------------------------------------- /.gitlab-ci.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.gitlab-ci.yml -------------------------------------------------------------------------------- /.goreleaser.yaml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.goreleaser.yaml -------------------------------------------------------------------------------- /.pre-commit-config.yaml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/.pre-commit-config.yaml -------------------------------------------------------------------------------- /CODE_OF_CONDUCT.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/CODE_OF_CONDUCT.md -------------------------------------------------------------------------------- /CONTRIBUTING.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/CONTRIBUTING.md -------------------------------------------------------------------------------- /DEPENDENCY.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/DEPENDENCY.md -------------------------------------------------------------------------------- /GOVERNANCE.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/GOVERNANCE.md -------------------------------------------------------------------------------- /INSTALL.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/INSTALL.md -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/LICENSE -------------------------------------------------------------------------------- /MAINTAINERS.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/MAINTAINERS.md -------------------------------------------------------------------------------- /Makefile: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/Makefile -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/README.md -------------------------------------------------------------------------------- /SECURITY-INSIGHTS.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/SECURITY-INSIGHTS.yml -------------------------------------------------------------------------------- /SECURITY.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/SECURITY.md -------------------------------------------------------------------------------- /arch.drawio.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/arch.drawio.png -------------------------------------------------------------------------------- /cmd/attestors.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/attestors.go -------------------------------------------------------------------------------- /cmd/attestors_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/attestors_test.go -------------------------------------------------------------------------------- /cmd/completion.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/completion.go -------------------------------------------------------------------------------- /cmd/completion_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/completion_test.go -------------------------------------------------------------------------------- /cmd/config.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/config.go -------------------------------------------------------------------------------- /cmd/keyloader.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/keyloader.go -------------------------------------------------------------------------------- /cmd/log.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/log.go -------------------------------------------------------------------------------- /cmd/log_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/log_test.go -------------------------------------------------------------------------------- /cmd/policy.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/policy.go -------------------------------------------------------------------------------- /cmd/policy_check.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/policy_check.go -------------------------------------------------------------------------------- /cmd/root.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/root.go -------------------------------------------------------------------------------- /cmd/root_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/root_test.go -------------------------------------------------------------------------------- /cmd/run.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/run.go -------------------------------------------------------------------------------- /cmd/run_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/run_test.go -------------------------------------------------------------------------------- /cmd/sign.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/sign.go -------------------------------------------------------------------------------- /cmd/sign_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/sign_test.go -------------------------------------------------------------------------------- /cmd/verify.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/verify.go -------------------------------------------------------------------------------- /cmd/verify_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/verify_test.go -------------------------------------------------------------------------------- /cmd/version.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/version.go -------------------------------------------------------------------------------- /cmd/version_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/cmd/version_test.go -------------------------------------------------------------------------------- /dev/.dockerignore: -------------------------------------------------------------------------------- 1 | .git 2 | -------------------------------------------------------------------------------- /dev/Dockerfile.go-builder: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/dev/Dockerfile.go-builder -------------------------------------------------------------------------------- /dev/build-and-push-builders.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/dev/build-and-push-builders.sh -------------------------------------------------------------------------------- /docgen/docs.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docgen/docs.go -------------------------------------------------------------------------------- /docgen/verify.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docgen/verify.sh -------------------------------------------------------------------------------- /docs-website/.env: -------------------------------------------------------------------------------- 1 | REACT_APP_IN_TOTO_SITE=witness // or 'archivista' based on your configuration 2 | -------------------------------------------------------------------------------- /docs-website/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/README.md -------------------------------------------------------------------------------- /docs-website/babel.config.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/babel.config.js -------------------------------------------------------------------------------- /docs-website/docusaurus.config.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/docusaurus.config.js -------------------------------------------------------------------------------- /docs-website/package.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/package.json -------------------------------------------------------------------------------- /docs-website/sidebars.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/sidebars.js -------------------------------------------------------------------------------- /docs-website/src/components/HomepageFeatures/index.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/src/components/HomepageFeatures/index.js -------------------------------------------------------------------------------- /docs-website/src/components/HomepageFeatures/styles.module.css: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/src/components/HomepageFeatures/styles.module.css -------------------------------------------------------------------------------- /docs-website/src/css/custom.css: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/src/css/custom.css -------------------------------------------------------------------------------- /docs-website/src/pages/index.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/src/pages/index.js -------------------------------------------------------------------------------- /docs-website/src/pages/index.module.css: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/src/pages/index.module.css -------------------------------------------------------------------------------- /docs-website/static/.nojekyll: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /docs-website/static/img/favicon.ico: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/favicon.ico -------------------------------------------------------------------------------- /docs-website/static/img/logo.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/logo.png -------------------------------------------------------------------------------- /docs-website/static/img/logo.svg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/logo.svg -------------------------------------------------------------------------------- /docs-website/static/img/undraw_alert_re_j2op.svg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/undraw_alert_re_j2op.svg -------------------------------------------------------------------------------- /docs-website/static/img/undraw_certificate_re_yadi.svg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/undraw_certificate_re_yadi.svg -------------------------------------------------------------------------------- /docs-website/static/img/undraw_hacker_mind_-6-y85.svg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/undraw_hacker_mind_-6-y85.svg -------------------------------------------------------------------------------- /docs-website/static/img/undraw_programmer_re_owql.svg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/undraw_programmer_re_owql.svg -------------------------------------------------------------------------------- /docs-website/static/img/witness-og.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/static/img/witness-og.png -------------------------------------------------------------------------------- /docs-website/yarn.lock: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs-website/yarn.lock -------------------------------------------------------------------------------- /docs/about/how-witness-works.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/about/how-witness-works.md -------------------------------------------------------------------------------- /docs/assets/arch.drawio.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/assets/arch.drawio.png -------------------------------------------------------------------------------- /docs/assets/attestation.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/assets/attestation.png -------------------------------------------------------------------------------- /docs/assets/demo.gif: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/assets/demo.gif -------------------------------------------------------------------------------- /docs/assets/logo.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/assets/logo.png -------------------------------------------------------------------------------- /docs/assets/verification.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/assets/verification.png -------------------------------------------------------------------------------- /docs/attestors/aws-codebuild.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/aws-codebuild.json -------------------------------------------------------------------------------- /docs/attestors/aws-codebuild.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/aws-codebuild.md -------------------------------------------------------------------------------- /docs/attestors/aws.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/aws.json -------------------------------------------------------------------------------- /docs/attestors/aws.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/aws.md -------------------------------------------------------------------------------- /docs/attestors/command-run.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/command-run.json -------------------------------------------------------------------------------- /docs/attestors/command-run.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/command-run.md -------------------------------------------------------------------------------- /docs/attestors/docker.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/docker.json -------------------------------------------------------------------------------- /docs/attestors/docker.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/docker.md -------------------------------------------------------------------------------- /docs/attestors/environment.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/environment.json -------------------------------------------------------------------------------- /docs/attestors/environment.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/environment.md -------------------------------------------------------------------------------- /docs/attestors/gcp-iit.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/gcp-iit.json -------------------------------------------------------------------------------- /docs/attestors/gcp-iit.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/gcp-iit.md -------------------------------------------------------------------------------- /docs/attestors/git.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/git.json -------------------------------------------------------------------------------- /docs/attestors/git.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/git.md -------------------------------------------------------------------------------- /docs/attestors/github.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/github.json -------------------------------------------------------------------------------- /docs/attestors/github.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/github.md -------------------------------------------------------------------------------- /docs/attestors/gitlab.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/gitlab.json -------------------------------------------------------------------------------- /docs/attestors/gitlab.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/gitlab.md -------------------------------------------------------------------------------- /docs/attestors/jenkins.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/jenkins.json -------------------------------------------------------------------------------- /docs/attestors/jenkins.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/jenkins.md -------------------------------------------------------------------------------- /docs/attestors/json.jsx: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/json.jsx -------------------------------------------------------------------------------- /docs/attestors/jwt.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/jwt.json -------------------------------------------------------------------------------- /docs/attestors/jwt.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/jwt.md -------------------------------------------------------------------------------- /docs/attestors/k8smanifest.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/k8smanifest.json -------------------------------------------------------------------------------- /docs/attestors/k8smanifest.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/k8smanifest.md -------------------------------------------------------------------------------- /docs/attestors/link.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/link.json -------------------------------------------------------------------------------- /docs/attestors/link.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/link.md -------------------------------------------------------------------------------- /docs/attestors/lockfiles.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/lockfiles.json -------------------------------------------------------------------------------- /docs/attestors/lockfiles.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/lockfiles.md -------------------------------------------------------------------------------- /docs/attestors/material.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/material.json -------------------------------------------------------------------------------- /docs/attestors/material.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/material.md -------------------------------------------------------------------------------- /docs/attestors/maven.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/maven.json -------------------------------------------------------------------------------- /docs/attestors/maven.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/maven.md -------------------------------------------------------------------------------- /docs/attestors/oci.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/oci.json -------------------------------------------------------------------------------- /docs/attestors/oci.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/oci.md -------------------------------------------------------------------------------- /docs/attestors/omnitrail.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/omnitrail.json -------------------------------------------------------------------------------- /docs/attestors/omnitrail.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/omnitrail.md -------------------------------------------------------------------------------- /docs/attestors/policyverify.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/policyverify.json -------------------------------------------------------------------------------- /docs/attestors/policyverify.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/policyverify.md -------------------------------------------------------------------------------- /docs/attestors/product.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/product.json -------------------------------------------------------------------------------- /docs/attestors/product.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/product.md -------------------------------------------------------------------------------- /docs/attestors/sarif.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/sarif.json -------------------------------------------------------------------------------- /docs/attestors/sarif.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/sarif.md -------------------------------------------------------------------------------- /docs/attestors/sbom.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/sbom.json -------------------------------------------------------------------------------- /docs/attestors/sbom.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/sbom.md -------------------------------------------------------------------------------- /docs/attestors/secretscan.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/secretscan.json -------------------------------------------------------------------------------- /docs/attestors/secretscan.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/secretscan.md -------------------------------------------------------------------------------- /docs/attestors/slsa.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/slsa.json -------------------------------------------------------------------------------- /docs/attestors/slsa.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/slsa.md -------------------------------------------------------------------------------- /docs/attestors/system-packages.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/system-packages.json -------------------------------------------------------------------------------- /docs/attestors/system-packages.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/system-packages.md -------------------------------------------------------------------------------- /docs/attestors/vex.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/vex.json -------------------------------------------------------------------------------- /docs/attestors/vex.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/attestors/vex.md -------------------------------------------------------------------------------- /docs/commands.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/commands.md -------------------------------------------------------------------------------- /docs/concepts/attestor.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/concepts/attestor.md -------------------------------------------------------------------------------- /docs/concepts/collection.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/concepts/collection.md -------------------------------------------------------------------------------- /docs/concepts/config.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/concepts/config.md -------------------------------------------------------------------------------- /docs/concepts/policy.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/concepts/policy.md -------------------------------------------------------------------------------- /docs/signers/kms.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/signers/kms.md -------------------------------------------------------------------------------- /docs/tutorials/artifact-policy.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/tutorials/artifact-policy.md -------------------------------------------------------------------------------- /docs/tutorials/getting-started.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/tutorials/getting-started.md -------------------------------------------------------------------------------- /docs/tutorials/sigstore-keyless.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/docs/tutorials/sigstore-keyless.md -------------------------------------------------------------------------------- /go.mod: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/go.mod -------------------------------------------------------------------------------- /go.sum: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/go.sum -------------------------------------------------------------------------------- /install-witness.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/install-witness.sh -------------------------------------------------------------------------------- /internal/policy/policy.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/internal/policy/policy.go -------------------------------------------------------------------------------- /internal/policy/policy_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/internal/policy/policy_test.go -------------------------------------------------------------------------------- /main.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/main.go -------------------------------------------------------------------------------- /netlify.toml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/netlify.toml -------------------------------------------------------------------------------- /options/options.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/options.go -------------------------------------------------------------------------------- /options/root.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/root.go -------------------------------------------------------------------------------- /options/root_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/root_test.go -------------------------------------------------------------------------------- /options/run.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/run.go -------------------------------------------------------------------------------- /options/run_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/run_test.go -------------------------------------------------------------------------------- /options/sign.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/sign.go -------------------------------------------------------------------------------- /options/sign_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/sign_test.go -------------------------------------------------------------------------------- /options/signers.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/signers.go -------------------------------------------------------------------------------- /options/verifiers.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/verifiers.go -------------------------------------------------------------------------------- /options/verify.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/verify.go -------------------------------------------------------------------------------- /options/verify_test.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/options/verify_test.go -------------------------------------------------------------------------------- /test/.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/.gitignore -------------------------------------------------------------------------------- /test/cdx-att.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/cdx-att.json -------------------------------------------------------------------------------- /test/cdx-sbom-policy-signed.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/cdx-sbom-policy-signed.json -------------------------------------------------------------------------------- /test/cdx-sbom-policy.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/cdx-sbom-policy.json -------------------------------------------------------------------------------- /test/common.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/common.sh -------------------------------------------------------------------------------- /test/failkey.pem: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/failkey.pem -------------------------------------------------------------------------------- /test/freetsa.pem: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/freetsa.pem -------------------------------------------------------------------------------- /test/fulcio-policy-signed.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/fulcio-policy-signed.json -------------------------------------------------------------------------------- /test/main.go: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/main.go -------------------------------------------------------------------------------- /test/policy-hello-signed.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/policy-hello-signed.json -------------------------------------------------------------------------------- /test/policy.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/policy.json -------------------------------------------------------------------------------- /test/sbom-policy-signed.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/sbom-policy-signed.json -------------------------------------------------------------------------------- /test/sbom.cdx.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/sbom.cdx.json -------------------------------------------------------------------------------- /test/sbom.spdx.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/sbom.spdx.json -------------------------------------------------------------------------------- /test/spdx-att.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/spdx-att.json -------------------------------------------------------------------------------- /test/spdx-sbom-policy-signed.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/spdx-sbom-policy-signed.json -------------------------------------------------------------------------------- /test/spdx-sbom-policy.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/spdx-sbom-policy.json -------------------------------------------------------------------------------- /test/test-mac.yaml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/test-mac.yaml -------------------------------------------------------------------------------- /test/test-oci.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/test-oci.sh -------------------------------------------------------------------------------- /test/test.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/test.json -------------------------------------------------------------------------------- /test/test.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/test.sh -------------------------------------------------------------------------------- /test/test.txt: -------------------------------------------------------------------------------- 1 | hello 2 | -------------------------------------------------------------------------------- /test/test.yaml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/test.yaml -------------------------------------------------------------------------------- /test/testkey.pem: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/testkey.pem -------------------------------------------------------------------------------- /test/testkey2.pem: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/testkey2.pem -------------------------------------------------------------------------------- /test/testpub.pem: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/testpub.pem -------------------------------------------------------------------------------- /test/testpub2.pem: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/in-toto/witness/HEAD/test/testpub2.pem --------------------------------------------------------------------------------