Commit graph

25 commits

Author SHA1 Message Date
Aditya Sirish A Yelgundhalli
3639e23219
*: Add gittuf sync
Signed-off-by: Aditya Sirish A Yelgundhalli <ayelgundhall@bloomberg.net>
2025-02-20 17:56:07 -05:00
Aditya Sirish
749b7df97c
*: Add support for coloring log output
Signed-off-by: Aditya Sirish <aditya@saky.in>
2025-02-01 17:58:11 -05:00
Aditya Sirish A Yelgundhalli
16d9e1d9ce
*: Move reference authorizations out of dev mode
Signed-off-by: Aditya Sirish A Yelgundhalli <ayelgundhall@bloomberg.net>
2025-01-31 13:45:23 -05:00
Aditya Sirish A Yelgundhalli
a601aee55d
*: Various policy fixes
1. VerifyMergeable was incorrectly returning an error when no verifiers were
found (for an unprotected base branch).

2. Policy's searcher interface was also returning the wrong error when the
latest policy or attestation entry was not found.

3. A verify-mergeable command has been added to simplify debugging.

Signed-off-by: Aditya Sirish A Yelgundhalli <ayelgundhall@bloomberg.net>
2024-12-06 16:08:32 -05:00
Pat Zielinski
d571facb8d *: Add copyright notice to code files
Signed-off-by: Pat Zielinski <70954403+patzielinski@users.noreply.github.com>
2024-09-27 15:28:12 -04:00
Aditya Sirish A Yelgundhalli
06b2d5713f *: Drop verify-{commit,tag} workflows
These workflows have some shortcomings, as discussed in
https://github.com/gittuf/gittuf/issues/384#issuecomment-2099153472.

verify-commit doesn't currently do enough to ensure the right policy is
identified for when a commit is first introduced. verify-ref, with some
enhancements, is better.

verify-tag implements a subset of verify-ref already because it recognizes tags
are refs. Thus, verify-ref is again a better option.

Signed-off-by: Aditya Sirish A Yelgundhalli <ayelgundhall@bloomberg.net>
2024-06-17 16:41:01 -04:00
Aditya Sirish
313509d3d9
cmd: Move apply to trust / policy cmds
For consistency, this makes apply a subcommand of both trust and policy
commands.

Signed-off-by: Aditya Sirish <aditya@saky.in>
2024-05-07 16:08:15 -04:00
neilnaveen
62be4b8360
Introduce Basic Staging Capabilities Utilizing the Policy Staging Ref
Fixed Docs and Lint Errors

Signed-off-by: neilnaveen <42328488+neilnaveen@users.noreply.github.com>
2024-04-26 10:16:57 -04:00
Aditya Sirish
d4547c998f
cmd: Add support for profiling via pprof
Signed-off-by: Aditya Sirish <aditya@saky.in>
2024-01-23 10:44:58 -05:00
Aditya Sirish
3fbf06a4e0
cmd: Update dev only commands
Signed-off-by: Aditya Sirish <aditya@saky.in>
2024-01-16 11:18:50 -05:00
Aditya Sirish
8d95538717
cmd: Add developer mode command
Signed-off-by: Aditya Sirish <aditya@saky.in>
2024-01-16 11:18:50 -05:00
Billy Lynch
0eb7030d71
Generate CLI docs.
Adds `DisableAutoGenTag: true` to disable timestamp in generated docs.

Signed-off-by: Billy Lynch <billy@chainguard.dev>
2024-01-12 11:50:27 -05:00
Aditya Sirish
c623bef04a
cmd: Support authorization attestations
Signed-off-by: Aditya Sirish <aditya@saky.in>
2024-01-03 11:11:54 -05:00
Fabian Kammel
eb49544db6
implement gittuf add-hooks to configure pre-push hook
Signed-off-by: Fabian Kammel <fabian.kammel@control-plane.io>
2023-12-20 11:31:12 +01:00
Fabian Kammel
0a3d8be142
don't print cli usage on error
Signed-off-by: Fabian Kammel <fabian.kammel@control-plane.io>
2023-12-18 15:37:45 +01:00
spectre10
d2186085b2
Add setup for logging with slog. Add verbose flag for logging at debug level.
Signed-off-by: spectre10 <shyamthakkar001@gmail.com>
2023-12-11 15:37:19 +05:30
Aditya Sirish
7cbc699879
cmd: Add version subcommand
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-10-23 13:12:38 -04:00
Aditya Sirish
5431e25aa7
cmd: Add clone
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-10-17 11:37:07 -04:00
Pat Zielinski
d0905e7816 Add SPDX License Identifiers to code files
Signed-off-by: Pat Zielinski <70954403+patzielinski@users.noreply.github.com>
2023-10-09 08:09:34 -04:00
Aditya Sirish
441d4c473e
*: Support verifying tags
In addition to gittuf verify-tag workflows, this commit fixes the RSL to
be more generic. An RSL entry no longer exclusively requires a commit
ID.

Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-10-04 11:22:33 -04:00
Aditya Sirish
30f583e7e4
*: Add verify-commit
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-10-02 10:47:14 -04:00
Aditya Sirish
3192cdb861
Rename module to use gittuf org
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-08-30 13:13:54 -04:00
Aditya Sirish
ec98685809
cmd: Add support for verification
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-07-14 10:48:22 -04:00
Aditya Sirish
9956b199fd
cmd: Add CLI commands for RSL manipulation
Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-06-20 13:48:03 -07:00
Aditya Sirish
31035b843c
cmd: Refactor entirely
This is a full fledged refactor of the cmd package based on this comment:
https://github.com/adityasaky/gittuf/pull/41#discussion_r1198995982.

First, the dev subcommand is retired as it was necessary to test certain
RSL functions which have now been built. The subcommand also printed out
the git config, again something we no longer need. To that end,
GetConfig() in gitinterface has been made private.

Second, the trust and policy subcommands have been reimplemented using
the recommended structure with specific packages that construct them
with their options.

Finally, the cmd package has been moved to the internal namespace.

Signed-off-by: Aditya Sirish <aditya@saky.in>
2023-05-20 15:17:11 -04:00