mirror of
https://github.com/vee1e/gittuf.git
synced 2026-09-03 03:07:10 +00:00
Restructure storage so gittuf verification can run over backends other
than the git binary (e.g. go-git):
- pkg/githash: concrete Git object hash, stdlib-only.
gitinterface.Hash aliases it.
- pkg/gitstore: the single Storer interface (24 methods) that all
storage consumers program against, plus the shared
ErrReferenceNotFound sentinel. *gitinterface.Repository satisfies it
structurally (compile-time asserted). Also defines ConfigKey, the
canonical type for the Git config settings gittuf reads.
- pkg/rsl (from internal/rsl): entry model, codec, and readers over
gitstore.Storer; zero gitinterface/sigstore dependencies. rsl.Hash
aliases githash.Hash; nil is the unset-Hash sentinel and IsZero
matches nil and empty as well as both format zeros (no
object-format-unaware ZeroHash). Entry commits (empty tree on the
RSL ref) are owned by the package; no storer adapter.
- internal/signerverifier/gitobject: verifies commit/tag signatures
over (payload, signature) bytes, Rekor URL as an option. The storage
half is Repository.GetObjectSignature. Removes sigstore, cosign, and
gitsign from gitinterface's dependency tree.
- internal/propagation: propagation workflow, moved off pkg/rsl's
public API (its tuf directive types are internal).
- internal/{attestations,cache,policy}: storage via gitstore.Storer;
tree writing via WriteTree(blobs, subtrees).
Breaking changes to pkg/gitinterface: Repository.VerifySignature and
the verification sentinels are removed (use gitobject.Verify);
ErrReferenceNotFound now aliases gitstore's. Repository.GetGitConfig
(which returned the whole config map) is replaced by
LookupConfig(gitstore.ConfigKey), returning a single setting's value.
Policy resolves the Rekor override from git config once per
verification and extracts signed payloads once per object instead of
per key attempt.
Assisted-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Paulo Gomes <paulo@entire.io>
|
||
|---|---|---|
| .. | ||
| blob.go | ||
| blob_test.go | ||
| changes.go | ||
| changes_test.go | ||
| commit.go | ||
| commit_test.go | ||
| common.go | ||
| common_test.go | ||
| config.go | ||
| config_test.go | ||
| hash.go | ||
| hash_test.go | ||
| log.go | ||
| log_test.go | ||
| object.go | ||
| object_test.go | ||
| README.md | ||
| references.go | ||
| references_test.go | ||
| remote.go | ||
| remote_test.go | ||
| replace_ref_test.go | ||
| repository.go | ||
| repository_test.go | ||
| signature.go | ||
| signature_test.go | ||
| status.go | ||
| status_test.go | ||
| sync.go | ||
| sync_test.go | ||
| tag.go | ||
| tag_test.go | ||
| tree.go | ||
| tree_test.go | ||
| utils.go | ||
| utils_test.go | ||
gittuf's gitinterface Package
gittuf's gitinterface package is a lightweight Go API for interacting with Git
repositories. It is similar to go-git in
its goal, but differs as, unlike go-git, gitinterface uses the Git binary
for its operations.
To operate correctly, gitinterface requires a Git binary version of 2.34 or
higher.