deb_control_files:
- control
- md5sums
deb_fields:
Architecture: arm64
Built-Using: docker-registry (= 2.8.3+ds1-2), docker.io (= 26.1.5+dfsg1-4), go-containerregistry
(= 0.20.1+ds1-1), golang-1.23 (= 1.23.5-1), golang-fsnotify (= 1.8.0-1), golang-github-asaskevich-govalidator
(= 11.0.1-1), golang-github-blang-semver (= 4.0.0-1), golang-github-cespare-xxhash
(= 2.3.0-1), golang-github-containerd-stargz-snapshotter (= 0.14.3-3), golang-github-coreos-go-oidc-v3
(= 3.4.0-2), golang-github-davecgh-go-spew (= 1.1.1-3), golang-github-digitorus-pkcs7
(= 0.0~git20230818.3a137a8-2), golang-github-digitorus-timestamp (= 0.0~git20231217.220c5c2-2),
golang-github-docker-docker-credential-helpers (= 0.6.4+ds1-1), golang-github-go-chi-chi
(= 5.2.0-1), golang-github-go-jose-go-jose.v3 (= 3.0.3-6), golang-github-go-logr-logr
(= 1.4.2-2), golang-github-go-logr-stdr (= 1.2.2-4), golang-github-go-openapi-analysis
(= 0.23.0-1), golang-github-go-openapi-errors (= 0.22.0-1), golang-github-go-openapi-jsonpointer
(= 1:0.21.0-1), golang-github-go-openapi-jsonreference (= 1:0.21.0-1), golang-github-go-openapi-loads
(= 0.22.0-1), golang-github-go-openapi-runtime (= 0.28.0-1), golang-github-go-openapi-spec
(= 1:0.21.0-1), golang-github-go-openapi-strfmt (= 0.23.0-1), golang-github-go-openapi-swag
(= 1:0.23.0-1), golang-github-go-openapi-validate (= 0.24.0-2), golang-github-google-certificate-transparency
(= 1.2.1-4), golang-github-google-uuid (= 1.6.0-1), golang-github-hashicorp-go-cleanhttp
(= 0.5.2-1), golang-github-hashicorp-go-retryablehttp (= 0.7.1-1), golang-github-hashicorp-hcl
(= 1.0.0-1.1), golang-github-in-toto-attestation (= 1.1.0-2), golang-github-jedisct1-go-minisign
(= 0.2.5-1), golang-github-josharian-intern (= 1.0.0-3), golang-github-klauspost-compress
(= 1.17.11+ds1-1), golang-github-magiconair-properties (= 1.8.7-1), golang-github-mailru-easyjson
(= 0.7.7-1), golang-github-mitchellh-go-homedir (= 1.1.0-1), golang-github-mitchellh-mapstructure
(= 1.5.0+git20231216.8508981-1), golang-github-oklog-ulid (= 2.0.2+ds-2), golang-github-opencontainers-go-digest
(= 1.0.0-2), golang-github-opencontainers-image-spec (= 1.1.0-2), golang-github-opentracing-opentracing-go
(= 1.2.0-2), golang-github-pelletier-go-toml.v2 (= 2.2.1-1), golang-github-pkg-errors
(= 0.9.1-3), golang-github-pmezard-go-difflib (= 1.0.0-3), golang-github-secure-systems-lab-go-securesystemslib
(= 0.9.0-1), golang-github-segmentio-ksuid (= 1.0.4-2), golang-github-shibumi-go-pathspec
(= 1.3.0-2), golang-github-sigstore-protobuf-specs (= 0.3.3-1), golang-github-sigstore-sigstore
(= 1.8.12-1), golang-github-sigstore-timestamp-authority (= 1.2.3-2), golang-github-skratchdot-open-golang
(= 0.0~git20160302.0.75fb7ed-2.1), golang-github-spf13-afero (= 1.11.0-1), golang-github-spf13-cast
(= 1.6.0-2), golang-github-spf13-cobra (= 1.8.1-1), golang-github-spf13-jwalterweatherman
(= 1.1.0+really1.1.0-2), golang-github-spf13-pflag (= 1.0.6~git20210604-d5e0c0615ace-1),
golang-github-spf13-viper (= 1.12.0-1), golang-github-subosito-gotenv (= 1.3.0-1),
golang-github-theupdateframework-go-tuf (= 2.0.2+0.7.0-1), golang-github-transparency-dev-merkle
(= 0.0.2-2), golang-github-vbatts-tar-split (= 0.11.6-1), golang-go.crypto (=
1:0.25.0-1), golang-go.uber-atomic (= 1.11.0-1), golang-go.uber-multierr (= 1.6.0-1),
golang-go.uber-zap (= 1.26.0-1), golang-golang-x-exp (= 0.0~git20231006.7918f67-1),
golang-golang-x-mod (= 0.19.0-1), golang-golang-x-net (= 1:0.27.0-1), golang-golang-x-oauth2
(= 0.15.0-1), golang-golang-x-sync (= 0.7.0-1), golang-golang-x-sys (= 0.22.0-1),
golang-golang-x-term (= 0.22.0-1), golang-golang-x-text (= 0.16.0-1), golang-google-genproto
(= 0.0~git20210726.e7812ac-4), golang-google-protobuf (= 1.33.0-1), golang-gopkg-ini.v1
(= 1.67.0-1), golang-gopkg-square-go-jose.v2 (= 2.6.3-3), golang-gopkg-yaml.v3
(= 3.0.1-3), golang-k8s-klog (= 2.130.1-1), golang-logrus (= 1.9.0-1), golang-mongodb-mongo-driver
(= 1.17.1+ds1-1), golang-opentelemetry-otel (= 1.31.0-3), golang-testify (= 1.9.0-1),
golang-webpki-org-jsoncanonicalizer (= 1.0.1-2), in-toto-golang (= 0.9.0+ds-3),
rekor (= 1.3.7-1), relic (= 7.6.1-2)
Depends: libc6 (>= 2.34)
Description: |-
Sigstore signing and verification (program)
A client library for Sigstore (https://www.sigstore.dev/), written in
Go. Features:
.
* Signing and verification of Sigstore bundles
(https://github.com/sigstore/protobuf-
specs/blob/main/protos/sigstore_bundle.proto) compliant with Sigstore
Client Spec
* Verification of raw Sigstore signatures by creating bundles for them
(see conformance tests (/cmd/conformance/main.go) for example)
* Signing and verifying with a Timestamp Authority (TSA)
* Signing and verifying (offline or online) with Rekor (Artifact
Transparency Log)
* Structured verification results including certificate metadata
* TUF support
* Verification support for custom trusted root
(https://github.com/sigstore/protobuf-
specs/blob/main/protos/sigstore_trustroot.proto)
* Basic CLI and examples
.
For an example of how to use this library, see the verification
documentation (/docs/verification.md), the CLI cmd/sigstore-go
(/cmd/sigstore-go/main.go). Note that the CLI
is to demonstrate how to use the library, and not intended as a fully-
featured Sigstore CLI like cosign (https://github.com/sigstore/cosign).
.
Background
.
Sigstore already has a canonical Go client implementation, cosign
(https://github.com/sigstore/cosign), which was developed with a focus
on container image signing/verification. It has a rich CLI and a long
legacy of features and development. sigstore-go is a more minimal and
friendly API for integrating Go code with Sigstore, with a focus on the
newly specified data structures in sigstore/protobuf-specs
(https://github.com/sigstore/protobuf-specs). sigstore-go attempts to
minimize the dependency tree for simple signing and verification tasks,
omitting KMS support and container image verification.
.
This package contains the binaries.
Homepage: https://github.com/sigstore/sigstore-go
Installed-Size: '55522'
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Package: sigstore-go
Priority: optional
Section: golang
Version: 0.6.2-1
srcpkg_name: sigstore-go
srcpkg_version: 0.6.2-1