mirror of
https://gitea.com/Lydanne/buildx.git
synced 2025-05-21 19:27:46 +08:00
Merge pull request #1498 from jedevc/attestation-printing
Improved attestation inspect
This commit is contained in:
commit
8340c40647
@ -287,22 +287,11 @@ $ docker buildx imagetools inspect moby/buildkit:master --format "{{json .Manife
|
|||||||
Following command provides [SLSA](https://github.com/moby/buildkit/blob/master/docs/attestations/slsa-provenance.md) JSON output:
|
Following command provides [SLSA](https://github.com/moby/buildkit/blob/master/docs/attestations/slsa-provenance.md) JSON output:
|
||||||
|
|
||||||
```console
|
```console
|
||||||
$ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .SLSA}}"
|
$ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .Provenance}}"
|
||||||
```
|
```
|
||||||
```json
|
```json
|
||||||
{
|
{
|
||||||
"Provenance": {
|
"SLSA": {
|
||||||
"_type": "https://in-toto.io/Statement/v0.1",
|
|
||||||
"predicateType": "https://slsa.dev/provenance/v0.2",
|
|
||||||
"subject": [
|
|
||||||
{
|
|
||||||
"name": "pkg:docker/crazymax/buildkit@attest?platform=linux%2Famd64",
|
|
||||||
"digest": {
|
|
||||||
"sha256": "fbd10fe50b4b174bb9ea273e2eb9827fa8bf5c88edd8635a93dc83e0d1aecb55"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"predicate": {
|
|
||||||
"builder": {
|
"builder": {
|
||||||
"id": ""
|
"id": ""
|
||||||
},
|
},
|
||||||
@ -352,7 +341,6 @@ $ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .SL
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
```
|
```
|
||||||
|
|
||||||
Following command provides [SBOM](https://github.com/moby/buildkit/blob/master/docs/attestations/sbom.md) JSON output:
|
Following command provides [SBOM](https://github.com/moby/buildkit/blob/master/docs/attestations/sbom.md) JSON output:
|
||||||
@ -363,17 +351,6 @@ $ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .SB
|
|||||||
```json
|
```json
|
||||||
{
|
{
|
||||||
"SPDX": {
|
"SPDX": {
|
||||||
"_type": "https://in-toto.io/Statement/v0.1",
|
|
||||||
"predicateType": "https://spdx.dev/Document",
|
|
||||||
"subject": [
|
|
||||||
{
|
|
||||||
"name": "pkg:docker/crazymax/buildkit@attest?platform=linux%2Famd64",
|
|
||||||
"digest": {
|
|
||||||
"sha256": "fbd10fe50b4b174bb9ea273e2eb9827fa8bf5c88edd8635a93dc83e0d1aecb55"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"predicate": {
|
|
||||||
"SPDXID": "SPDXRef-DOCUMENT",
|
"SPDXID": "SPDXRef-DOCUMENT",
|
||||||
"creationInfo": {
|
"creationInfo": {
|
||||||
"created": "2022-12-01T11:46:48.063400162Z",
|
"created": "2022-12-01T11:46:48.063400162Z",
|
||||||
@ -390,7 +367,6 @@ $ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .SB
|
|||||||
"spdxVersion": "SPDX-2.2"
|
"spdxVersion": "SPDX-2.2"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
```
|
```
|
||||||
|
|
||||||
```console
|
```console
|
||||||
@ -465,19 +441,8 @@ $ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .}}
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"SLSA": {
|
|
||||||
"Provenance": {
|
"Provenance": {
|
||||||
"_type": "https://in-toto.io/Statement/v0.1",
|
"SLSA": {
|
||||||
"predicateType": "https://slsa.dev/provenance/v0.2",
|
|
||||||
"subject": [
|
|
||||||
{
|
|
||||||
"name": "pkg:docker/crazymax/buildkit@attest?platform=linux%2Famd64",
|
|
||||||
"digest": {
|
|
||||||
"sha256": "fbd10fe50b4b174bb9ea273e2eb9827fa8bf5c88edd8635a93dc83e0d1aecb55"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"predicate": {
|
|
||||||
"builder": {
|
"builder": {
|
||||||
"id": ""
|
"id": ""
|
||||||
},
|
},
|
||||||
@ -526,21 +491,9 @@ $ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .}}
|
|||||||
"https://mobyproject.org/buildkit@v1#metadata": {}
|
"https://mobyproject.org/buildkit@v1#metadata": {}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
},
|
},
|
||||||
"SBOM": {
|
"SBOM": {
|
||||||
"SPDX": {
|
"SPDX": {
|
||||||
"_type": "https://in-toto.io/Statement/v0.1",
|
|
||||||
"predicateType": "https://spdx.dev/Document",
|
|
||||||
"subject": [
|
|
||||||
{
|
|
||||||
"name": "pkg:docker/crazymax/buildkit@attest?platform=linux%2Famd64",
|
|
||||||
"digest": {
|
|
||||||
"sha256": "fbd10fe50b4b174bb9ea273e2eb9827fa8bf5c88edd8635a93dc83e0d1aecb55"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"predicate": {
|
|
||||||
"SPDXID": "SPDXRef-DOCUMENT",
|
"SPDXID": "SPDXRef-DOCUMENT",
|
||||||
"creationInfo": {
|
"creationInfo": {
|
||||||
"created": "2022-12-01T11:46:48.063400162Z",
|
"created": "2022-12-01T11:46:48.063400162Z",
|
||||||
@ -558,7 +511,6 @@ $ docker buildx imagetools inspect crazymax/buildkit:attest --format "{{json .}}
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
```
|
```
|
||||||
|
|
||||||
#### Multi-platform
|
#### Multi-platform
|
||||||
|
@ -48,7 +48,7 @@ type index struct {
|
|||||||
type asset struct {
|
type asset struct {
|
||||||
config *ocispec.Image
|
config *ocispec.Image
|
||||||
sbom *sbomStub
|
sbom *sbomStub
|
||||||
slsa *slsaStub
|
provenance *provenanceStub
|
||||||
}
|
}
|
||||||
|
|
||||||
type result struct {
|
type result struct {
|
||||||
@ -255,7 +255,8 @@ func (l *loader) scanConfig(ctx context.Context, fetcher remotes.Fetcher, desc o
|
|||||||
}
|
}
|
||||||
|
|
||||||
type sbomStub struct {
|
type sbomStub struct {
|
||||||
SPDX json.RawMessage `json:",omitempty"`
|
SPDX interface{} `json:",omitempty"`
|
||||||
|
AdditionalSPDXs []interface{} `json:",omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
func (l *loader) scanSBOM(ctx context.Context, fetcher remotes.Fetcher, r *result, refs []digest.Digest, as *asset) error {
|
func (l *loader) scanSBOM(ctx context.Context, fetcher remotes.Fetcher, r *result, refs []digest.Digest, as *asset) error {
|
||||||
@ -275,8 +276,18 @@ func (l *loader) scanSBOM(ctx context.Context, fetcher remotes.Fetcher, r *resul
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
as.sbom = &sbomStub{
|
var spdx struct {
|
||||||
SPDX: dt,
|
Predicate interface{} `json:"predicate"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal(dt, &spdx); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
if as.sbom == nil {
|
||||||
|
as.sbom = &sbomStub{}
|
||||||
|
as.sbom.SPDX = spdx.Predicate
|
||||||
|
} else {
|
||||||
|
as.sbom.AdditionalSPDXs = append(as.sbom.AdditionalSPDXs, spdx.Predicate)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@ -284,8 +295,8 @@ func (l *loader) scanSBOM(ctx context.Context, fetcher remotes.Fetcher, r *resul
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
type slsaStub struct {
|
type provenanceStub struct {
|
||||||
Provenance json.RawMessage `json:",omitempty"`
|
SLSA interface{} `json:",omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
func (l *loader) scanProvenance(ctx context.Context, fetcher remotes.Fetcher, r *result, refs []digest.Digest, as *asset) error {
|
func (l *loader) scanProvenance(ctx context.Context, fetcher remotes.Fetcher, r *result, refs []digest.Digest, as *asset) error {
|
||||||
@ -305,9 +316,16 @@ func (l *loader) scanProvenance(ctx context.Context, fetcher remotes.Fetcher, r
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
as.slsa = &slsaStub{
|
var slsa struct {
|
||||||
Provenance: dt,
|
Predicate interface{} `json:"predicate"`
|
||||||
}
|
}
|
||||||
|
if err := json.Unmarshal(dt, &slsa); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
as.provenance = &provenanceStub{
|
||||||
|
SLSA: slsa.Predicate,
|
||||||
|
}
|
||||||
|
break
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@ -328,16 +346,16 @@ func (r *result) Configs() map[string]*ocispec.Image {
|
|||||||
return res
|
return res
|
||||||
}
|
}
|
||||||
|
|
||||||
func (r *result) SLSA() map[string]slsaStub {
|
func (r *result) Provenance() map[string]provenanceStub {
|
||||||
if len(r.assets) == 0 {
|
if len(r.assets) == 0 {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
res := make(map[string]slsaStub)
|
res := make(map[string]provenanceStub)
|
||||||
for p, a := range r.assets {
|
for p, a := range r.assets {
|
||||||
if a.slsa == nil {
|
if a.provenance == nil {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
res[p] = *a.slsa
|
res[p] = *a.provenance
|
||||||
}
|
}
|
||||||
return res
|
return res
|
||||||
}
|
}
|
||||||
|
@ -99,7 +99,7 @@ func (p *Printer) Print(raw bool, out io.Writer) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
imageconfigs := res.Configs()
|
imageconfigs := res.Configs()
|
||||||
slsas := res.SLSA()
|
provenances := res.Provenance()
|
||||||
sboms := res.SBOM()
|
sboms := res.SBOM()
|
||||||
format := tpl.Root.String()
|
format := tpl.Root.String()
|
||||||
|
|
||||||
@ -146,13 +146,13 @@ func (p *Printer) Print(raw bool, out io.Writer) error {
|
|||||||
Name string `json:"name,omitempty"`
|
Name string `json:"name,omitempty"`
|
||||||
Manifest interface{} `json:"manifest,omitempty"`
|
Manifest interface{} `json:"manifest,omitempty"`
|
||||||
Image map[string]*ocispecs.Image `json:"image,omitempty"`
|
Image map[string]*ocispecs.Image `json:"image,omitempty"`
|
||||||
SLSA map[string]slsaStub `json:"SLSA,omitempty"`
|
Provenance map[string]provenanceStub `json:"Provenance,omitempty"`
|
||||||
SBOM map[string]sbomStub `json:"SBOM,omitempty"`
|
SBOM map[string]sbomStub `json:"SBOM,omitempty"`
|
||||||
}{
|
}{
|
||||||
Name: p.name,
|
Name: p.name,
|
||||||
Manifest: mfst,
|
Manifest: mfst,
|
||||||
Image: imageconfigs,
|
Image: imageconfigs,
|
||||||
SLSA: slsas,
|
Provenance: provenances,
|
||||||
SBOM: sboms,
|
SBOM: sboms,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@ -160,9 +160,9 @@ func (p *Printer) Print(raw bool, out io.Writer) error {
|
|||||||
for _, v := range imageconfigs {
|
for _, v := range imageconfigs {
|
||||||
ic = v
|
ic = v
|
||||||
}
|
}
|
||||||
var slsa slsaStub
|
var provenance provenanceStub
|
||||||
for _, v := range slsas {
|
for _, v := range provenances {
|
||||||
slsa = v
|
provenance = v
|
||||||
}
|
}
|
||||||
var sbom sbomStub
|
var sbom sbomStub
|
||||||
for _, v := range sboms {
|
for _, v := range sboms {
|
||||||
@ -172,13 +172,13 @@ func (p *Printer) Print(raw bool, out io.Writer) error {
|
|||||||
Name string `json:"name,omitempty"`
|
Name string `json:"name,omitempty"`
|
||||||
Manifest interface{} `json:"manifest,omitempty"`
|
Manifest interface{} `json:"manifest,omitempty"`
|
||||||
Image *ocispecs.Image `json:"image,omitempty"`
|
Image *ocispecs.Image `json:"image,omitempty"`
|
||||||
SLSA slsaStub `json:"SLSA,omitempty"`
|
Provenance provenanceStub `json:"Provenance,omitempty"`
|
||||||
SBOM sbomStub `json:"SBOM,omitempty"`
|
SBOM sbomStub `json:"SBOM,omitempty"`
|
||||||
}{
|
}{
|
||||||
Name: p.name,
|
Name: p.name,
|
||||||
Manifest: mfst,
|
Manifest: mfst,
|
||||||
Image: ic,
|
Image: ic,
|
||||||
SLSA: slsa,
|
Provenance: provenance,
|
||||||
SBOM: sbom,
|
SBOM: sbom,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user